Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 12.2.0
Report Generated On : Mon, 19 Jan 2026 20:55:39 GMT
Dependencies Scanned : 46 (31 unique)
Vulnerable Dependencies : 1
Vulnerabilities Found : 18
Vulnerabilities Suppressed : 0
...
NVD API Last Checked : 2026-01-19T20:29:50Z
NVD API Last Modified : 2026-01-19T20:15:49Z
Summary
Summary of Vulnerable Dependencies (click to show all)
* indicates the dependency has a known exploited vulnerability
asm-9.9.1.jar
Description:
ASM, a very small and fast Java bytecode manipulation framework
License:
BSD-3-Clause: https://asm.ow2.io/license.html
File Path: /home/runner/.m2/repository/org/ow2/asm/asm/9.9.1/asm-9.9.1.jar
MD5: 1888ad1f49038441bb2d12aa6dffe396
SHA1: 2ceea6ab43bcae1979b2a6d85fc0ca429877e5ab
SHA256: 6f3828a215c920059a5efa2fb55c233d6c54ec5cadca99ce1b1bdd10077c7ddd
Referenced In Project/Scope: waffle-jetty:provided
asm-9.9.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.ow2.asm/asm-commons@9.9.1
Evidence
Type Source Name Value Confidence
Vendor file name asm High
Vendor jar package name asm Highest
Vendor jar package name objectweb Highest
Vendor Manifest bundle-docurl http://asm.ow2.org Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor Manifest bundle-symbolicname org.objectweb.asm Medium
Vendor pom artifactid asm Highest
Vendor pom artifactid asm Low
Vendor pom developer email ebruneton@free.fr Low
Vendor pom developer email eu@javatx.org Low
Vendor pom developer email forax@univ-mlv.fr Low
Vendor pom developer id ebruneton Medium
Vendor pom developer id eu Medium
Vendor pom developer id forax Medium
Vendor pom developer name Eric Bruneton Medium
Vendor pom developer name Eugene Kuleshov Medium
Vendor pom developer name Remi Forax Medium
Vendor pom groupid org.ow2.asm Highest
Vendor pom name asm High
Vendor pom organization name OW2 High
Vendor pom organization url http://www.ow2.org/ Medium
Vendor pom parent-artifactid ow2 Low
Vendor pom parent-groupid org.ow2 Medium
Vendor pom url http://asm.ow2.io/ Highest
Product file name asm High
Product jar package name asm Highest
Product jar package name objectweb Highest
Product Manifest bundle-docurl http://asm.ow2.org Low
Product Manifest Bundle-Name org.objectweb.asm Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest bundle-symbolicname org.objectweb.asm Medium
Product Manifest Implementation-Title ASM, a very small and fast Java bytecode manipulation framework High
Product pom artifactid asm Highest
Product pom developer email ebruneton@free.fr Low
Product pom developer email eu@javatx.org Low
Product pom developer email forax@univ-mlv.fr Low
Product pom developer id ebruneton Low
Product pom developer id eu Low
Product pom developer id forax Low
Product pom developer name Eric Bruneton Low
Product pom developer name Eugene Kuleshov Low
Product pom developer name Remi Forax Low
Product pom groupid org.ow2.asm Highest
Product pom name asm High
Product pom organization name OW2 Low
Product pom organization url http://www.ow2.org/ Low
Product pom parent-artifactid ow2 Medium
Product pom parent-groupid org.ow2 Medium
Product pom url http://asm.ow2.io/ Medium
Version file version 9.9.1 High
Version Manifest Bundle-Version 9.9.1 High
Version Manifest Implementation-Version 9.9.1 High
Version pom parent-version 9.9.1 Low
Version pom version 9.9.1 Highest
pkg:maven/org.ow2.asm/asm@9.9.1
(Confidence :High)
asm-commons-9.9.1.jar
Description:
Usefull class adapters based on ASM, a very small and fast Java bytecode manipulation framework
License:
BSD-3-Clause: https://asm.ow2.io/license.html
File Path: /home/runner/.m2/repository/org/ow2/asm/asm-commons/9.9.1/asm-commons-9.9.1.jar
MD5: 7e0ef716c43d92d29e666f820df24e2c
SHA1: ab35de4c537184a09339069f1a3b3aacf2289149
SHA256: c2319e014ce7199f2b7f7d56d6bb991863168c3f4b6cd6c9f542a4937ef7ef88
Referenced In Project/Scope: waffle-jetty:provided
asm-commons-9.9.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-jetty@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name asm-commons High
Vendor jar package name asm Highest
Vendor jar package name commons Highest
Vendor jar package name objectweb Highest
Vendor Manifest bundle-docurl http://asm.ow2.org Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor Manifest bundle-symbolicname org.objectweb.asm.commons Medium
Vendor Manifest module-requires org.objectweb.asm;transitive=true,org.objectweb.asm.tree;transitive=true Low
Vendor pom artifactid asm-commons Highest
Vendor pom artifactid asm-commons Low
Vendor pom developer email ebruneton@free.fr Low
Vendor pom developer email eu@javatx.org Low
Vendor pom developer email forax@univ-mlv.fr Low
Vendor pom developer id ebruneton Medium
Vendor pom developer id eu Medium
Vendor pom developer id forax Medium
Vendor pom developer name Eric Bruneton Medium
Vendor pom developer name Eugene Kuleshov Medium
Vendor pom developer name Remi Forax Medium
Vendor pom groupid org.ow2.asm Highest
Vendor pom name asm-commons High
Vendor pom organization name OW2 High
Vendor pom organization url http://www.ow2.org/ Medium
Vendor pom parent-artifactid ow2 Low
Vendor pom parent-groupid org.ow2 Medium
Vendor pom url http://asm.ow2.io/ Highest
Product file name asm-commons High
Product jar package name asm Highest
Product jar package name commons Highest
Product jar package name objectweb Highest
Product Manifest bundle-docurl http://asm.ow2.org Low
Product Manifest Bundle-Name org.objectweb.asm.commons Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest bundle-symbolicname org.objectweb.asm.commons Medium
Product Manifest Implementation-Title Usefull class adapters based on ASM, a very small and fast Java bytecode manipulation framework High
Product Manifest module-requires org.objectweb.asm;transitive=true,org.objectweb.asm.tree;transitive=true Low
Product pom artifactid asm-commons Highest
Product pom developer email ebruneton@free.fr Low
Product pom developer email eu@javatx.org Low
Product pom developer email forax@univ-mlv.fr Low
Product pom developer id ebruneton Low
Product pom developer id eu Low
Product pom developer id forax Low
Product pom developer name Eric Bruneton Low
Product pom developer name Eugene Kuleshov Low
Product pom developer name Remi Forax Low
Product pom groupid org.ow2.asm Highest
Product pom name asm-commons High
Product pom organization name OW2 Low
Product pom organization url http://www.ow2.org/ Low
Product pom parent-artifactid ow2 Medium
Product pom parent-groupid org.ow2 Medium
Product pom url http://asm.ow2.io/ Medium
Version file version 9.9.1 High
Version Manifest Bundle-Version 9.9.1 High
Version Manifest Implementation-Version 9.9.1 High
Version pom parent-version 9.9.1 Low
Version pom version 9.9.1 Highest
pkg:maven/org.ow2.asm/asm-commons@9.9.1
(Confidence :High)
asm-tree-9.9.1.jar
Description:
Tree API of ASM, a very small and fast Java bytecode manipulation framework
License:
BSD-3-Clause: https://asm.ow2.io/license.html
File Path: /home/runner/.m2/repository/org/ow2/asm/asm-tree/9.9.1/asm-tree-9.9.1.jar
MD5: 7eb17cd0d09b03fbe473e51edfc6e4d2
SHA1: b6b1b3366296163b4b1f540731aad0a2baa484d8
SHA256: 0f3555096b720b820bbacab0b515589bee0200bee099bda14c561738ae837ba1
Referenced In Project/Scope: waffle-jetty:provided
asm-tree-9.9.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.ow2.asm/asm-commons@9.9.1
Evidence
Type Source Name Value Confidence
Vendor file name asm-tree High
Vendor jar package name asm Highest
Vendor jar package name objectweb Highest
Vendor jar package name tree Highest
Vendor Manifest bundle-docurl http://asm.ow2.org Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor Manifest bundle-symbolicname org.objectweb.asm.tree Medium
Vendor Manifest module-requires org.objectweb.asm;transitive=true Low
Vendor pom artifactid asm-tree Highest
Vendor pom artifactid asm-tree Low
Vendor pom developer email ebruneton@free.fr Low
Vendor pom developer email eu@javatx.org Low
Vendor pom developer email forax@univ-mlv.fr Low
Vendor pom developer id ebruneton Medium
Vendor pom developer id eu Medium
Vendor pom developer id forax Medium
Vendor pom developer name Eric Bruneton Medium
Vendor pom developer name Eugene Kuleshov Medium
Vendor pom developer name Remi Forax Medium
Vendor pom groupid org.ow2.asm Highest
Vendor pom name asm-tree High
Vendor pom organization name OW2 High
Vendor pom organization url http://www.ow2.org/ Medium
Vendor pom parent-artifactid ow2 Low
Vendor pom parent-groupid org.ow2 Medium
Vendor pom url http://asm.ow2.io/ Highest
Product file name asm-tree High
Product jar package name asm Highest
Product jar package name objectweb Highest
Product jar package name tree Highest
Product Manifest bundle-docurl http://asm.ow2.org Low
Product Manifest Bundle-Name org.objectweb.asm.tree Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest bundle-symbolicname org.objectweb.asm.tree Medium
Product Manifest Implementation-Title Tree API of ASM, a very small and fast Java bytecode manipulation framework High
Product Manifest module-requires org.objectweb.asm;transitive=true Low
Product pom artifactid asm-tree Highest
Product pom developer email ebruneton@free.fr Low
Product pom developer email eu@javatx.org Low
Product pom developer email forax@univ-mlv.fr Low
Product pom developer id ebruneton Low
Product pom developer id eu Low
Product pom developer id forax Low
Product pom developer name Eric Bruneton Low
Product pom developer name Eugene Kuleshov Low
Product pom developer name Remi Forax Low
Product pom groupid org.ow2.asm Highest
Product pom name asm-tree High
Product pom organization name OW2 Low
Product pom organization url http://www.ow2.org/ Low
Product pom parent-artifactid ow2 Medium
Product pom parent-groupid org.ow2 Medium
Product pom url http://asm.ow2.io/ Medium
Version file version 9.9.1 High
Version Manifest Bundle-Version 9.9.1 High
Version Manifest Implementation-Version 9.9.1 High
Version pom parent-version 9.9.1 Low
Version pom version 9.9.1 Highest
pkg:maven/org.ow2.asm/asm-tree@9.9.1
(Confidence :High)
caffeine-3.2.3.jar
Description:
A high performance caching library
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/github/ben-manes/caffeine/caffeine/3.2.3/caffeine-3.2.3.jar
MD5: 0258f45d43968523cc11beeb01b240f2
SHA1: c097f0f6d21a0e6db88ea55836e26419b30dfe19
SHA256: ca70c90a5d1ce1511880ce9c93d4ad22108f61111d3daf91eb52762b571bd179
Referenced In Project/Scope: waffle-jetty:compile
caffeine-3.2.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name caffeine High
Vendor jar package name cache Highest
Vendor jar package name caffeine Highest
Vendor jar package name github Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-symbolicname com.github.ben-manes.caffeine Medium
Vendor pom artifactid caffeine Highest
Vendor pom artifactid caffeine Low
Vendor pom developer email ben.manes@gmail.com Low
Vendor pom developer id ben-manes Medium
Vendor pom developer name Ben Manes Medium
Vendor pom groupid com.github.ben-manes.caffeine Highest
Vendor pom name Caffeine cache High
Vendor pom url ben-manes/caffeine Highest
Product file name caffeine High
Product jar package name cache Highest
Product jar package name caffeine Highest
Product jar package name github Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Bundle-Name com.github.ben-manes.caffeine Medium
Product Manifest bundle-symbolicname com.github.ben-manes.caffeine Medium
Product Manifest Implementation-Title A high performance caching library High
Product pom artifactid caffeine Highest
Product pom developer email ben.manes@gmail.com Low
Product pom developer id ben-manes Low
Product pom developer name Ben Manes Low
Product pom groupid com.github.ben-manes.caffeine Highest
Product pom name Caffeine cache High
Product pom url ben-manes/caffeine High
Version file version 3.2.3 High
Version Manifest Bundle-Version 3.2.3 High
Version Manifest Implementation-Version 3.2.3 High
Version pom version 3.2.3 Highest
pkg:maven/com.github.ben-manes.caffeine/caffeine@3.2.3
(Confidence :High)
checker-qual-3.53.0.jar
Description:
checker-qual contains annotations (type qualifiers) that a programmerwrites to specify Java code for type-checking by the Checker Framework.
License:
The MIT License: http://opensource.org/licenses/MIT
File Path: /home/runner/.m2/repository/org/checkerframework/checker-qual/3.53.0/checker-qual-3.53.0.jar
MD5: d1ee2a3366a19a8fff01208da2adb48e
SHA1: af1105964a03d7ed8aaf8ea2cb6ec0da7ec6c7a6
SHA256: 7ca002815d92fad79e966b375c2ee7b2b4bf953024bc9a5d5e0c59df13ff5af8
Referenced In Project/Scope: waffle-jetty:compile
checker-qual-3.53.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name checker-qual High
Vendor jar package name checker Highest
Vendor jar package name checkerframework Highest
Vendor jar package name framework Highest
Vendor jar package name qual Highest
Vendor Manifest bundle-symbolicname checker-qual Medium
Vendor Manifest implementation-url https://checkerframework.org Low
Vendor pom artifactid checker-qual Highest
Vendor pom artifactid checker-qual Low
Vendor pom developer email mernst@cs.washington.edu Low
Vendor pom developer email smillst@cs.washington.edu Low
Vendor pom developer id mernst Medium
Vendor pom developer id smillst Medium
Vendor pom developer name Michael Ernst Medium
Vendor pom developer name Suzanne Millstein Medium
Vendor pom developer org University of Washington Medium
Vendor pom developer org URL https://www.cs.washington.edu/ Medium
Vendor pom groupid org.checkerframework Highest
Vendor pom name Checker Qual High
Vendor pom url https://checkerframework.org/ Highest
Product file name checker-qual High
Product jar package name checker Highest
Product jar package name checkerframework Highest
Product jar package name framework Highest
Product jar package name qual Highest
Product Manifest Bundle-Name checker-qual Medium
Product Manifest bundle-symbolicname checker-qual Medium
Product Manifest implementation-url https://checkerframework.org Low
Product pom artifactid checker-qual Highest
Product pom developer email mernst@cs.washington.edu Low
Product pom developer email smillst@cs.washington.edu Low
Product pom developer id mernst Low
Product pom developer id smillst Low
Product pom developer name Michael Ernst Low
Product pom developer name Suzanne Millstein Low
Product pom developer org University of Washington Low
Product pom developer org URL https://www.cs.washington.edu/ Low
Product pom groupid org.checkerframework Highest
Product pom name Checker Qual High
Product pom url https://checkerframework.org/ Medium
Version file version 3.53.0 High
Version Manifest Bundle-Version 3.53.0 High
Version Manifest Implementation-Version 3.53.0 High
Version pom version 3.53.0 Highest
pkg:maven/org.checkerframework/checker-qual@3.53.0
(Confidence :High)
com.github.waffle:waffle-jna:3.6.0-SNAPSHOT
Description:
WAFFLE JNA implementation
License:
MIT https://raw.github.com/Waffle/waffle/master/LICENSE
File Path: /home/runner/work/waffle/waffle/Source/JNA/waffle-jna/pom.xml
Referenced In Project/Scope: waffle-jetty
com.github.waffle:waffle-jna:3.6.0-SNAPSHOT is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-jetty@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name pom High
Vendor project artifactid waffle-jna Low
Vendor project groupid com.github.waffle Highest
Product file name pom High
Product project artifactid waffle-jna Highest
Product project groupid com.github.waffle Low
pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
(Confidence :Highest)
ecj-3.44.0.jar
Description:
Eclipse Compiler for Java(TM)
License:
EPL-2.0: https://www.eclipse.org/legal/epl-2.0/
File Path: /home/runner/.m2/repository/org/eclipse/jdt/ecj/3.44.0/ecj-3.44.0.jar
MD5: 8d0d2b80bc3d9431f0bdf3037f3d5954
SHA1: a4e1c9f58954801783e1b49d2f281000f814a779
SHA256: 14c46ddc2e511c46c998da728f6a80f13a689c920f3832402f7ad150f6a6188d
Referenced In Project/Scope: waffle-jetty:provided
ecj-3.44.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-jetty@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name ecj High
Vendor jar package name compiler Highest
Vendor jar package name core Highest
Vendor jar package name eclipse Highest
Vendor jar package name jdt Highest
Vendor Manifest automatic-module-name org.eclipse.jdt.core.compiler.batch Medium
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-17 Low
Vendor Manifest bundle-symbolicname org.eclipse.jdt.core.compiler.batch Medium
Vendor pom artifactid ecj Highest
Vendor pom artifactid ecj Low
Vendor pom groupid org.eclipse.jdt Highest
Vendor pom name Eclipse Compiler for Java(TM) High
Vendor pom organization name Eclipse Foundation High
Vendor pom organization url https://www.eclipse.org Medium
Vendor pom url eclipse-jdt/eclipse.jdt.core/ Highest
Product file name ecj High
Product jar package name compiler Highest
Product jar package name core Highest
Product jar package name eclipse Highest
Product jar package name jdt Highest
Product Manifest automatic-module-name org.eclipse.jdt.core.compiler.batch Medium
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest Bundle-Name Eclipse Compiler for Java(TM) Medium
Product Manifest bundle-requiredexecutionenvironment JavaSE-17 Low
Product Manifest bundle-symbolicname org.eclipse.jdt.core.compiler.batch Medium
Product pom artifactid ecj Highest
Product pom groupid org.eclipse.jdt Highest
Product pom name Eclipse Compiler for Java(TM) High
Product pom organization name Eclipse Foundation Low
Product pom organization url https://www.eclipse.org Low
Product pom url eclipse-jdt/eclipse.jdt.core/ High
Version file version 3.44.0 High
Version pom version 3.44.0 Highest
pkg:maven/org.eclipse.jdt/ecj@3.44.0
(Confidence :High)
error_prone_annotations-2.46.0.jar
Description:
Error Prone is a static analysis tool for Java that catches common programming mistakes at compile-time.
License:
Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/google/errorprone/error_prone_annotations/2.46.0/error_prone_annotations-2.46.0.jar
MD5: d0dabea249c067d21d7eb997fbdf5c99
SHA1: 4ecb5d2392c38c46e6cb65e1bf60be708d97005d
SHA256: b67be81ff4b956401146e14eaf1526bc435a9480f2546e91eb45b796631a8a99
Referenced In Project/Scope: waffle-jetty:provided
error_prone_annotations-2.46.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-jetty@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name error_prone_annotations High
Vendor jar package name annotations Highest
Vendor jar package name errorprone Highest
Vendor jar package name google Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://errorprone.info/error_prone_annotations Low
Vendor Manifest bundle-symbolicname com.google.errorprone.annotations Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid error_prone_annotations Highest
Vendor pom artifactid error_prone_annotations Low
Vendor pom groupid com.google.errorprone Highest
Vendor pom name error-prone annotations High
Vendor pom parent-artifactid error_prone_parent Low
Product file name error_prone_annotations High
Product jar package name annotations Highest
Product jar package name errorprone Highest
Product jar package name google Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://errorprone.info/error_prone_annotations Low
Product Manifest Bundle-Name error-prone annotations Medium
Product Manifest bundle-symbolicname com.google.errorprone.annotations Medium
Product Manifest multi-release true Low
Product pom artifactid error_prone_annotations Highest
Product pom groupid com.google.errorprone Highest
Product pom name error-prone annotations High
Product pom parent-artifactid error_prone_parent Medium
Version file version 2.46.0 High
Version Manifest Bundle-Version 2.46.0 High
Version pom version 2.46.0 Highest
pkg:maven/com.google.errorprone/error_prone_annotations@2.46.0
(Confidence :High)
j2objc-annotations-3.1.jar
Description:
A set of annotations that provide additional information to the J2ObjC
translator to modify the result of translation.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/google/j2objc/j2objc-annotations/3.1/j2objc-annotations-3.1.jar
MD5: abe8bd3abff622b9a8b15c3a737aa741
SHA1: a892ca9507839bbdb900d64310ac98256cab992f
SHA256: 84d3a150518485f8140ea99b8a985656749629f6433c92b80c75b36aba3b099b
Referenced In Project/Scope: waffle-jetty:provided
j2objc-annotations-3.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-jetty@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name j2objc-annotations High
Vendor jar package name annotations Highest
Vendor jar package name google Highest
Vendor jar package name j2objc Highest
Vendor Manifest build-jdk-spec 22 Low
Vendor Manifest multi-release true Low
Vendor pom artifactid j2objc-annotations Highest
Vendor pom artifactid j2objc-annotations Low
Vendor pom developer email tball@google.com Low
Vendor pom developer id tomball Medium
Vendor pom developer name Tom Ball Medium
Vendor pom developer org Google Medium
Vendor pom developer org URL https://www.google.com Medium
Vendor pom groupid com.google.j2objc Highest
Vendor pom name J2ObjC Annotations High
Vendor pom url google/j2objc/ Highest
Product file name j2objc-annotations High
Product jar package name annotations Highest
Product jar package name google Highest
Product jar package name j2objc Highest
Product Manifest build-jdk-spec 22 Low
Product Manifest multi-release true Low
Product pom artifactid j2objc-annotations Highest
Product pom developer email tball@google.com Low
Product pom developer id tomball Low
Product pom developer name Tom Ball Low
Product pom developer org Google Low
Product pom developer org URL https://www.google.com Low
Product pom groupid com.google.j2objc Highest
Product pom name J2ObjC Annotations High
Product pom url google/j2objc/ High
Version file version 3.1 High
Version pom version 3.1 Highest
pkg:maven/com.google.j2objc/j2objc-annotations@3.1
(Confidence :High)
jakarta.annotation-api-3.0.0.jar
Description:
Jakarta Annotations API
License:
EPL 2.0: https://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /home/runner/.m2/repository/jakarta/annotation/jakarta.annotation-api/3.0.0/jakarta.annotation-api-3.0.0.jar
MD5: 7faffaab962918da4cf5ddfd76609dd2
SHA1: 54f928fadec906a99d558536756d171917b9d936
SHA256: b01f55552284cfb149411e64eabca75e942d26d2e1786b32914250e4330afaa2
Referenced In Project/Scope: waffle-jetty:provided
jakarta.annotation-api-3.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-jetty@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.annotation-api High
Vendor jar package name annotation Highest
Vendor jar package name jakarta Highest
Vendor Manifest build-jdk-spec 18 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.annotation-api Medium
Vendor Manifest extension-name jakarta.annotation Medium
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.annotation-api Highest
Vendor pom artifactid jakarta.annotation-api Low
Vendor pom developer name Dmitry Kornilov Medium
Vendor pom developer name Linda De Michiel Medium
Vendor pom developer org Oracle Corp. Medium
Vendor pom groupid jakarta.annotation Highest
Vendor pom name Jakarta Annotations API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://projects.eclipse.org/projects/ee4j.ca Highest
Product file name jakarta.annotation-api High
Product jar package name annotation Highest
Product jar package name jakarta Highest
Product Manifest build-jdk-spec 18 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Annotations API Medium
Product Manifest bundle-symbolicname jakarta.annotation-api Medium
Product Manifest extension-name jakarta.annotation Medium
Product pom artifactid jakarta.annotation-api Highest
Product pom developer name Dmitry Kornilov Low
Product pom developer name Linda De Michiel Low
Product pom developer org Oracle Corp. Low
Product pom groupid jakarta.annotation Highest
Product pom name Jakarta Annotations API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://projects.eclipse.org/projects/ee4j.ca Medium
Version file version 3.0.0 High
Version Manifest Bundle-Version 3.0.0 High
Version Manifest Implementation-Version 3.0.0 High
Version pom parent-version 3.0.0 Low
Version pom version 3.0.0 Highest
pkg:maven/jakarta.annotation/jakarta.annotation-api@3.0.0
(Confidence :High)
cpe:2.3:a:oracle:projects:3.0.0:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jakarta.el-3.0.4.jar
Description:
Jakarta Expression Language provides a specification document, API, reference implementation and TCK
that describes an expression language for Java applications.
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /home/runner/.m2/repository/org/glassfish/jakarta.el/3.0.4/jakarta.el-3.0.4.jar
MD5: a4ff0d711c405e054f8166c2ea893e0e
SHA1: f48473482c0e3e714f87186d9305bcae30b7f5cb
SHA256: 3b8d4311b47fb47d168ad4338b6649a7cc21d5066b9765bd28ebca93148064be
Referenced In Project/Scope: waffle-jetty:provided
jakarta.el-3.0.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-jetty@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.el High
Vendor jar package name el Highest
Vendor jar package name expression Highest
Vendor jar package name javax Highest
Vendor jar package name sun Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname com.sun.el.javax.el Medium
Vendor Manifest extension-name javax.el Medium
Vendor Manifest Implementation-Vendor Oracle Corporation High
Vendor Manifest specification-vendor Oracle Corporation Low
Vendor pom artifactid jakarta.el Highest
Vendor pom artifactid jakarta.el Low
Vendor pom developer id yaminikb Medium
Vendor pom developer name Yamini K B Medium
Vendor pom developer org Oracle Corporation Medium
Vendor pom developer org URL http://www.oracle.com/ Medium
Vendor pom groupid org.glassfish Highest
Vendor pom name Jakarta Expression Language 3.0 High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://projects.eclipse.org/projects/ee4j.el Highest
Product file name jakarta.el High
Product jar package name el Highest
Product jar package name expression Highest
Product jar package name javax Highest
Product jar package name sun Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Expression Language 3.0 Medium
Product Manifest bundle-symbolicname com.sun.el.javax.el Medium
Product Manifest extension-name javax.el Medium
Product pom artifactid jakarta.el Highest
Product pom developer id yaminikb Low
Product pom developer name Yamini K B Low
Product pom developer org Oracle Corporation Low
Product pom developer org URL http://www.oracle.com/ Low
Product pom groupid org.glassfish Highest
Product pom name Jakarta Expression Language 3.0 High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://projects.eclipse.org/projects/ee4j.el Medium
Version file version 3.0.4 High
Version Manifest Bundle-Version 3.0.4 High
Version Manifest Implementation-Version 3.0.4 High
Version pom parent-version 3.0.4 Low
Version pom version 3.0.4 Highest
pkg:maven/org.glassfish/jakarta.el@3.0.4
(Confidence :High)
cpe:2.3:a:eclipse:jakarta_expression_language:3.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jakarta.el-api-6.0.1.jar
Description:
Jakarta Expression Language defines an expression language for Java applications
License:
https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt, https://www.gnu.org/software/classpath/license.html
File Path: /home/runner/.m2/repository/jakarta/el/jakarta.el-api/6.0.1/jakarta.el-api-6.0.1.jar
MD5: a98f097e059552a75748fcdd067e5c16
SHA1: c7c4a2eb1e40e0ff45ab5e2e52bd77d8c7a75176
SHA256: 7e84b5bed49de32b79cc5e85d90b6f5adb1a953ac67283adbb41c1e297f9c605
Referenced In Project/Scope: waffle-jetty:provided
jakarta.el-api-6.0.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-jetty@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.el-api High
Vendor jar package name el Highest
Vendor jar package name expression Highest
Vendor jar package name jakarta Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.el-api Medium
Vendor Manifest extension-name jakarta.el Medium
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.el-api Highest
Vendor pom artifactid jakarta.el-api Low
Vendor pom developer email el-dev@eclipse.org Low
Vendor pom developer id jakarta-ee4j-el Medium
Vendor pom developer name Jakarta Expression Language Developers Medium
Vendor pom developer org Eclipse Foundation Medium
Vendor pom groupid jakarta.el Highest
Vendor pom name Jakarta Expression Language API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://projects.eclipse.org/projects/ee4j.el Highest
Product file name jakarta.el-api High
Product jar package name el Highest
Product jar package name expression Highest
Product jar package name jakarta Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Expression Language API Medium
Product Manifest bundle-symbolicname jakarta.el-api Medium
Product Manifest extension-name jakarta.el Medium
Product pom artifactid jakarta.el-api Highest
Product pom developer email el-dev@eclipse.org Low
Product pom developer id jakarta-ee4j-el Low
Product pom developer name Jakarta Expression Language Developers Low
Product pom developer org Eclipse Foundation Low
Product pom groupid jakarta.el Highest
Product pom name Jakarta Expression Language API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://projects.eclipse.org/projects/ee4j.el Medium
Version file version 6.0.1 High
Version Manifest Bundle-Version 6.0.1 High
Version Manifest Implementation-Version 6.0.1 High
Version pom parent-version 6.0.1 Low
Version pom version 6.0.1 Highest
pkg:maven/jakarta.el/jakarta.el-api@6.0.1
(Confidence :High)
cpe:2.3:a:eclipse:jakarta_expression_language:6.0.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jakarta.servlet-api-4.0.2.jar
Description:
Java(TM) Servlet 4.0 API Design Specification
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /home/runner/.m2/repository/jakarta/servlet/jakarta.servlet-api/4.0.2/jakarta.servlet-api-4.0.2.jar
MD5: 75523dea16c815e4b111796ea1679b1b
SHA1: 60da427ed588aa0cf70cb6cb7209c31e83069364
SHA256: 0cd32c92320ae92c8692ef326dfeef756e97760251fca0c45472f299f1c3c916
Referenced In Project/Scope: waffle-jetty:provided
jakarta.servlet-api-4.0.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.glassfish.web/jakarta.servlet.jsp.jstl@1.2.6
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.servlet-api High
Vendor jar package name javax Highest
Vendor jar package name servlet Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.servlet-api Medium
Vendor Manifest extension-name javax.servlet Medium
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest specification-vendor Oracle Corporation Low
Vendor pom artifactid jakarta.servlet-api Highest
Vendor pom artifactid jakarta.servlet-api Low
Vendor pom developer id yaminikb Medium
Vendor pom developer name Yamini K B Medium
Vendor pom developer org Oracle Corporation Medium
Vendor pom developer org URL http://www.oracle.com/ Medium
Vendor pom groupid jakarta.servlet Highest
Vendor pom name Java Servlet API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://projects.eclipse.org/projects/ee4j.servlet Highest
Product file name jakarta.servlet-api High
Product jar package name javax Highest
Product jar package name servlet Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Java Servlet API Medium
Product Manifest bundle-symbolicname jakarta.servlet-api Medium
Product Manifest extension-name javax.servlet Medium
Product pom artifactid jakarta.servlet-api Highest
Product pom developer id yaminikb Low
Product pom developer name Yamini K B Low
Product pom developer org Oracle Corporation Low
Product pom developer org URL http://www.oracle.com/ Low
Product pom groupid jakarta.servlet Highest
Product pom name Java Servlet API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://projects.eclipse.org/projects/ee4j.servlet Medium
Version file version 4.0.2 High
Version Manifest Implementation-Version 4.0.2 High
Version pom parent-version 4.0.2 Low
Version pom version 4.0.2 Highest
jakarta.servlet.jsp-2.3.6.jar
Description:
JavaServer Pages API
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /home/runner/.m2/repository/org/glassfish/web/jakarta.servlet.jsp/2.3.6/jakarta.servlet.jsp-2.3.6.jar
MD5: 16d8baeceb5503f066c61582085c75cb
SHA1: 13192d5874b787c0ce0c70b35e95181e8b683a1c
SHA256: 990af769158db75833fe8b4d1e56ea778246bc3c6522d434369f1a0bcebf8582
Referenced In Project/Scope: waffle-jetty:provided
jakarta.servlet.jsp-2.3.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-jetty@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.servlet.jsp High
Vendor jar package name api Highest
Vendor jar package name glassfish Highest
Vendor jar package name jsp Highest
Vendor jar package name servlet Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname org.glassfish.web.jakarta.servlet.jsp Medium
Vendor Manifest extension-name javax.servlet.jsp Medium
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.servlet.jsp Highest
Vendor pom artifactid jakarta.servlet.jsp Low
Vendor pom developer id yaminikb Medium
Vendor pom developer name Yamini K B Medium
Vendor pom developer org Oracle Corporation Medium
Vendor pom developer org URL http://www.oracle.com Medium
Vendor pom groupid org.glassfish.web Highest
Vendor pom name JSP implementation High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://projects.eclipse.org/projects/ee4j.jsp Highest
Product file name jakarta.servlet.jsp High
Product jar package name api Highest
Product jar package name glassfish Highest
Product jar package name jsp Highest
Product jar package name servlet Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name JSP implementation Medium
Product Manifest bundle-symbolicname org.glassfish.web.jakarta.servlet.jsp Medium
Product Manifest extension-name javax.servlet.jsp Medium
Product pom artifactid jakarta.servlet.jsp Highest
Product pom developer id yaminikb Low
Product pom developer name Yamini K B Low
Product pom developer org Oracle Corporation Low
Product pom developer org URL http://www.oracle.com Low
Product pom groupid org.glassfish.web Highest
Product pom name JSP implementation High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://projects.eclipse.org/projects/ee4j.jsp Medium
Version file version 2.3.6 High
Version Manifest Bundle-Version 2.3.6 High
Version Manifest Implementation-Version 2.3.6 High
Version pom parent-version 2.3.6 Low
Version pom version 2.3.6 Highest
jakarta.servlet.jsp-api-4.0.0.jar
Description:
Jakarta Server Pages API
License:
https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt, https://www.gnu.org/software/classpath/license.html
File Path: /home/runner/.m2/repository/jakarta/servlet/jsp/jakarta.servlet.jsp-api/4.0.0/jakarta.servlet.jsp-api-4.0.0.jar
MD5: 6fddc938119e00e6f934c1b37120e338
SHA1: a8de3741b91ba7427306104979ab2f084e831438
SHA256: 873b7d0c2b5734ef8847634299b67ce879080cdece8426147522c4db8e37c14e
Referenced In Project/Scope: waffle-jetty:provided
jakarta.servlet.jsp-api-4.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-jetty@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.servlet.jsp-api High
Vendor jar package name jakarta Highest
Vendor jar package name jsp Highest
Vendor jar package name servlet Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.servlet.jsp-api Medium
Vendor Manifest extension-name jakarta.servlet.jsp Medium
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.servlet.jsp-api Highest
Vendor pom artifactid jakarta.servlet.jsp-api Low
Vendor pom developer email jsp-dev@eclipse.org Low
Vendor pom developer id jakarta-ee4j-jsp Medium
Vendor pom developer name Jakarta Server Pages Developers Medium
Vendor pom developer org Eclipse Foundation Medium
Vendor pom groupid jakarta.servlet.jsp Highest
Vendor pom name Jakarta Server Pages API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://projects.eclipse.org/projects/ee4j.jsp Highest
Product file name jakarta.servlet.jsp-api High
Product jar package name jakarta Highest
Product jar package name jsp Highest
Product jar package name servlet Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Server Pages API Medium
Product Manifest bundle-symbolicname jakarta.servlet.jsp-api Medium
Product Manifest extension-name jakarta.servlet.jsp Medium
Product pom artifactid jakarta.servlet.jsp-api Highest
Product pom developer email jsp-dev@eclipse.org Low
Product pom developer id jakarta-ee4j-jsp Low
Product pom developer name Jakarta Server Pages Developers Low
Product pom developer org Eclipse Foundation Low
Product pom groupid jakarta.servlet.jsp Highest
Product pom name Jakarta Server Pages API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://projects.eclipse.org/projects/ee4j.jsp Medium
Version file version 4.0.0 High
Version Manifest Bundle-Version 4.0.0 High
Version Manifest Implementation-Version 4.0.0 High
Version pom parent-version 4.0.0 Low
Version pom version 4.0.0 Highest
pkg:maven/jakarta.servlet.jsp/jakarta.servlet.jsp-api@4.0.0
(Confidence :High)
jakarta.servlet.jsp.jstl-1.2.6.jar
Description:
JavaServer Pages(TM) Standard Tag Library API
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /home/runner/.m2/repository/org/glassfish/web/jakarta.servlet.jsp.jstl/1.2.6/jakarta.servlet.jsp.jstl-1.2.6.jar
MD5: 7058e8ed0b161b729e6134784750d22b
SHA1: f5a092de3b2b087c14ca4b8d6f2c77a1f6802828
SHA256: 3b697c6cdf4d28de185e07d63f3682728b5a2b1dd229f5f9deb9b930d64b484a
Referenced In Project/Scope: waffle-jetty:provided
jakarta.servlet.jsp.jstl-1.2.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-jetty@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.servlet.jsp.jstl High
Vendor jar package name oracle Highest
Vendor jar package name org Highest
Vendor jar package name standard Highest
Vendor jar package name tag Highest
Vendor jar (hint) package name sun Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname org.glassfish.web.jakarta.servlet.jsp.jstl Medium
Vendor Manifest extension-name javax.servlet.jsp.jstl Medium
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest originally-created-by 1.8.0_181 (Oracle Corporation) Low
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.servlet.jsp.jstl Highest
Vendor pom artifactid jakarta.servlet.jsp.jstl Low
Vendor pom developer id yaminikb Medium
Vendor pom developer name Yamini K B Medium
Vendor pom developer org Oracle Corporation Medium
Vendor pom developer org URL http://www.oracle.com/ Medium
Vendor pom groupid org.glassfish.web Highest
Vendor pom name JavaServer Pages (TM) TagLib Implementation High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://projects.eclipse.org/projects/ee4j.jstl Highest
Product file name jakarta.servlet.jsp.jstl High
Product jar package name oracle Highest
Product jar package name org Highest
Product jar package name standard Highest
Product jar package name tag Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name JavaServer Pages (TM) TagLib Implementation Medium
Product Manifest bundle-symbolicname org.glassfish.web.jakarta.servlet.jsp.jstl Medium
Product Manifest extension-name javax.servlet.jsp.jstl Medium
Product Manifest originally-created-by 1.8.0_181 (Oracle Corporation) Low
Product pom artifactid jakarta.servlet.jsp.jstl Highest
Product pom developer id yaminikb Low
Product pom developer name Yamini K B Low
Product pom developer org Oracle Corporation Low
Product pom developer org URL http://www.oracle.com/ Low
Product pom groupid org.glassfish.web Highest
Product pom name JavaServer Pages (TM) TagLib Implementation High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://projects.eclipse.org/projects/ee4j.jstl Medium
Version file version 1.2.6 High
Version Manifest Bundle-Version 1.2.6 High
Version Manifest Implementation-Version 1.2.6 High
Version pom parent-version 1.2.6 Low
Version pom version 1.2.6 Highest
jakarta.servlet.jsp.jstl-api-1.2.4.jar
Description:
JavaServer Pages(TM) Standard Tag Library API
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /home/runner/.m2/repository/jakarta/servlet/jsp/jstl/jakarta.servlet.jsp.jstl-api/1.2.4/jakarta.servlet.jsp.jstl-api-1.2.4.jar
MD5: 5b4683c3a614b37a5de721817e792024
SHA1: 9d23cda192df1192894277fd9d0710abb61329af
SHA256: 57122ab0151f82e716d825e65627e8064eb108dbeaafafa780687d61d5359454
Referenced In Project/Scope: waffle-jetty:provided
jakarta.servlet.jsp.jstl-api-1.2.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.glassfish.web/jakarta.servlet.jsp.jstl@1.2.6
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.servlet.jsp.jstl-api High
Vendor jar package name javax Highest
Vendor jar package name jsp Highest
Vendor jar package name jstl Highest
Vendor jar package name servlet Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.servlet.jsp.jstl-api Medium
Vendor Manifest extension-name javax.servlet.jsp.jstl Medium
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest originally-created-by 1.8.0_181 (Oracle Corporation) Low
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.servlet.jsp.jstl-api Highest
Vendor pom artifactid jakarta.servlet.jsp.jstl-api Low
Vendor pom developer id yaminikb Medium
Vendor pom developer name Yamini K B Medium
Vendor pom developer org Oracle Corporation Medium
Vendor pom developer org URL http://www.oracle.com/ Medium
Vendor pom groupid jakarta.servlet.jsp.jstl Highest
Vendor pom name JavaServer Pages(TM) Standard Tag Library API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://projects.eclipse.org/projects/ee4j.jstl Highest
Product file name jakarta.servlet.jsp.jstl-api High
Product jar package name javax Highest
Product jar package name jsp Highest
Product jar package name jstl Highest
Product jar package name servlet Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name JavaServer Pages(TM) Standard Tag Library API Medium
Product Manifest bundle-symbolicname jakarta.servlet.jsp.jstl-api Medium
Product Manifest extension-name javax.servlet.jsp.jstl Medium
Product Manifest originally-created-by 1.8.0_181 (Oracle Corporation) Low
Product pom artifactid jakarta.servlet.jsp.jstl-api Highest
Product pom developer id yaminikb Low
Product pom developer name Yamini K B Low
Product pom developer org Oracle Corporation Low
Product pom developer org URL http://www.oracle.com/ Low
Product pom groupid jakarta.servlet.jsp.jstl Highest
Product pom name JavaServer Pages(TM) Standard Tag Library API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://projects.eclipse.org/projects/ee4j.jstl Medium
Version file version 1.2.4 High
Version Manifest Bundle-Version 1.2.4 High
Version Manifest Implementation-Version 1.2.4 High
Version pom parent-version 1.2.4 Low
Version pom version 1.2.4 Highest
jetty-io-12.1.5.jar
Description:
Jetty module for Core :: IO
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/eclipse/jetty/jetty-io/12.1.5/jetty-io-12.1.5.jar
MD5: 7dc223f8ff9aa14da8de2c4802153215
SHA1: de8db8fc9b571209b9d46321acf920238e02c143
SHA256: 9c388018412d9bd9a1b9c35ca373e25fd845706f82549f2a7039ae9fefb45e69
Referenced In Project/Scope: waffle-jetty:provided
jetty-io-12.1.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.eclipse.jetty/jetty-client@12.1.5
Evidence
Type Source Name Value Confidence
Vendor file name jetty-io High
Vendor jar package name eclipse Highest
Vendor jar package name io Highest
Vendor jar package name jetty Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.io Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-io Highest
Vendor pom artifactid jetty-io Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: IO High
Vendor pom parent-artifactid jetty-core Low
Product file name jetty-io High
Product jar package name eclipse Highest
Product jar package name io Highest
Product jar package name jetty Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: IO Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.io Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-io Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: IO High
Product pom parent-artifactid jetty-core Medium
Version file version 12.1.5 High
Version Manifest Bundle-Version 12.1.5 High
Version Manifest Implementation-Version 12.1.5 High
Version pom version 12.1.5 Highest
Related Dependencies
jetty-alpn-client-12.1.5.jar
File Path: /home/runner/.m2/repository/org/eclipse/jetty/jetty-alpn-client/12.1.5/jetty-alpn-client-12.1.5.jar
MD5: f41dda56c2b2af661aa0e9b468008453
SHA1: 437fcfda64db5cdbf7d01cb9a8268c1685495510
SHA256: a4fe9fe0f4d6eae1d7c4010e9c04ffdf6222e02a6b684fa90f04e109825954f1
pkg:maven/org.eclipse.jetty/jetty-alpn-client@12.1.5
jetty-client-12.1.5.jar
File Path: /home/runner/.m2/repository/org/eclipse/jetty/jetty-client/12.1.5/jetty-client-12.1.5.jar
MD5: 1d4af694005ec52dccb515cc6d6089f3
SHA1: 596fd1f6d68214c8abdf3bb5e0650c977c1f2506
SHA256: ddcff35a3a1b1f5266bbc78324a7ece4af45717383efbea227aab5918bdc942b
pkg:maven/org.eclipse.jetty/jetty-client@12.1.5
jetty-compression-common-12.1.5.jar
File Path: /home/runner/.m2/repository/org/eclipse/jetty/compression/jetty-compression-common/12.1.5/jetty-compression-common-12.1.5.jar
MD5: 5dc82c221aeeec11cede481f5b387cdc
SHA1: 73041a5d99e33d85b2ee5219a737d9d749583012
SHA256: f9eaa16477daaf7ff41e5489e6d41268c42cd58888396762ef093ace819ab683
pkg:maven/org.eclipse.jetty.compression/jetty-compression-common@12.1.5
jetty-compression-gzip-12.1.5.jar
File Path: /home/runner/.m2/repository/org/eclipse/jetty/compression/jetty-compression-gzip/12.1.5/jetty-compression-gzip-12.1.5.jar
MD5: aa9164859e2fa6439114a5e7ba5d0c70
SHA1: 886991f101138ecebd6a1c7f86fdbe23baa2533a
SHA256: f9a3b082a4eeb0013226c9fd9e9dd60f77c1bf93a87d95e741be9553e769c7b5
pkg:maven/org.eclipse.jetty.compression/jetty-compression-gzip@12.1.5
jetty-ee-webapp-12.1.5.jar
File Path: /home/runner/.m2/repository/org/eclipse/jetty/ee/jetty-ee-webapp/12.1.5/jetty-ee-webapp-12.1.5.jar
MD5: 62e1b8c894e1a2c213e72937816c9f6f
SHA1: 9a5b35fdb0eaadb92d17eb57e76c98b607f64f8b
SHA256: 520f82e932e7dee3b7d2bc4207c0b287815247d6c813df01a054cf3517a08982
pkg:maven/org.eclipse.jetty.ee/jetty-ee-webapp@12.1.5
jetty-ee8-apache-jsp-12.1.5.jar
File Path: /home/runner/.m2/repository/org/eclipse/jetty/ee8/jetty-ee8-apache-jsp/12.1.5/jetty-ee8-apache-jsp-12.1.5.jar
MD5: 8f20a0be00dd92e1be1b7247601193a3
SHA1: c5a5015008f637250159ce58252069c25607516d
SHA256: 08f6f0cef68548d32cc0bd4a15faa0aaebc35a3592f6cef35d4540e3a0014d46
pkg:maven/org.eclipse.jetty.ee8/jetty-ee8-apache-jsp@12.1.5
jetty-ee8-nested-12.1.5.jar
File Path: /home/runner/.m2/repository/org/eclipse/jetty/ee8/jetty-ee8-nested/12.1.5/jetty-ee8-nested-12.1.5.jar
MD5: 3b113e152069a95a14e399a5c37b274b
SHA1: 26f3090e3e95629da5b5f79944f067a4acb5e646
SHA256: 0bcc1d92d6dc482bac55979b6c9d7756f8b061295fc41cf2713354f9bd464c38
pkg:maven/org.eclipse.jetty.ee8/jetty-ee8-nested@12.1.5
jetty-ee8-security-12.1.5.jar
File Path: /home/runner/.m2/repository/org/eclipse/jetty/ee8/jetty-ee8-security/12.1.5/jetty-ee8-security-12.1.5.jar
MD5: 72768ea6f5a114514f1f8215ccaa2b79
SHA1: 231b911f11d9bd445eede6b984b9a1f772d8e509
SHA256: 789ba4518cd2848563473d636270b42c541d34cf79bed36c84e3ce811f76c2cd
pkg:maven/org.eclipse.jetty.ee8/jetty-ee8-security@12.1.5
jetty-ee8-servlet-12.1.5.jar
File Path: /home/runner/.m2/repository/org/eclipse/jetty/ee8/jetty-ee8-servlet/12.1.5/jetty-ee8-servlet-12.1.5.jar
MD5: aa15caa38aac9d83bdab95fc05bc201e
SHA1: 6b3b60d6e017cc4c76c07dbfbf8ca094eee49272
SHA256: 3c27e08483b1f2860e727c7577e094e63af595159dabe28022dd4e10e37f12b0
pkg:maven/org.eclipse.jetty.ee8/jetty-ee8-servlet@12.1.5
jetty-ee8-webapp-12.1.5.jar
File Path: /home/runner/.m2/repository/org/eclipse/jetty/ee8/jetty-ee8-webapp/12.1.5/jetty-ee8-webapp-12.1.5.jar
MD5: b96993908fe71e9c2a6a1b8cd3799c56
SHA1: 7519b6047a5d27157c0ba231cde04dd8f195e7c6
SHA256: 7940927022bd2ad82097b497e4b59c5d4502a8e9e3934e379b43ec74c6574478
pkg:maven/org.eclipse.jetty.ee8/jetty-ee8-webapp@12.1.5
jetty-http-12.1.5.jar
File Path: /home/runner/.m2/repository/org/eclipse/jetty/jetty-http/12.1.5/jetty-http-12.1.5.jar
MD5: 5a5bb13aaa8df3dbae10a0d3fa09538b
SHA1: 6e3bb3127cb6aa99a1c6aef18f018847f7b52828
SHA256: 20a6f605e802789990855b81f75dadfa8ab152e81713080c295c333d7cce7daa
pkg:maven/org.eclipse.jetty/jetty-http@12.1.5
jetty-security-12.1.5.jar
File Path: /home/runner/.m2/repository/org/eclipse/jetty/jetty-security/12.1.5/jetty-security-12.1.5.jar
MD5: c8dcb33295f83f78e300c789905c3ad3
SHA1: d511e0ad42e5fac3b3534fafba3e129ff233d779
SHA256: 9972b67058ad7a58a0517cd14502e67e2e1071c74b00f51c6487518f0bfdc02e
pkg:maven/org.eclipse.jetty/jetty-security@12.1.5
jetty-session-12.1.5.jar
File Path: /home/runner/.m2/repository/org/eclipse/jetty/jetty-session/12.1.5/jetty-session-12.1.5.jar
MD5: fee495181da152373d1061b6b00c8da1
SHA1: 603a5b27f446c5461e9ba1e02fa19f7cdec75ab4
SHA256: ebe4f30c6fe7656294d884e1dc8eea4c77b6c861e3c010847a76fd78164ae166
pkg:maven/org.eclipse.jetty/jetty-session@12.1.5
jetty-util-12.1.5.jar
File Path: /home/runner/.m2/repository/org/eclipse/jetty/jetty-util/12.1.5/jetty-util-12.1.5.jar
MD5: 46f9168c80abdce7b9f8c7f599801287
SHA1: 6f0e8a796fa183e5f771b2349490a16ae08c0e18
SHA256: 3b165498c1409db1a2463c367250c9225635cf68cd4529fbb0610324942bbc07
pkg:maven/org.eclipse.jetty/jetty-util@12.1.5
jetty-xml-12.1.5.jar
File Path: /home/runner/.m2/repository/org/eclipse/jetty/jetty-xml/12.1.5/jetty-xml-12.1.5.jar
MD5: 97c201b37497bc418cc3f006a77ce6d6
SHA1: 9985351623f6f73a1b324f9242f28e28a25e9810
SHA256: ec514c229a60a1be448b2771fc09644195966390cc413d09567f109a9362497c
pkg:maven/org.eclipse.jetty/jetty-xml@12.1.5
jetty-server-12.1.5.jar
Description:
The legacy jetty server artifact.
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/eclipse/jetty/jetty-server/12.1.5/jetty-server-12.1.5.jar
MD5: f56663610098daa47c5138401a5762fe
SHA1: df890fa50e1de86bb130113a59baf874d647b5dd
SHA256: e0964741f132de3bdb48ca59c4b9bb8555f966d46b660c8c88f1e157cedbaa02
Referenced In Project/Scope: waffle-jetty:provided
jetty-server-12.1.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.eclipse.jetty.ee8/jetty-ee8-servlet@12.1.5
Evidence
Type Source Name Value Confidence
Vendor file name jetty-server High
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor jar package name server Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.server Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-server Highest
Vendor pom artifactid jetty-server Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: Server High
Vendor pom parent-artifactid jetty-core Low
Product file name jetty-server High
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product jar package name server Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: Server Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.server Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-server Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: Server High
Product pom parent-artifactid jetty-core Medium
Version file version 12.1.5 High
Version Manifest Bundle-Version 12.1.5 High
Version Manifest Implementation-Version 12.1.5 High
Version pom version 12.1.5 Highest
jetty-servlet-api-4.0.6.jar
Description:
Combined servlet api and schemas for use in JPMS and OSGi environments
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.eclipse.org/org/documents/epl-v10.php
File Path: /home/runner/.m2/repository/org/eclipse/jetty/toolchain/jetty-servlet-api/4.0.6/jetty-servlet-api-4.0.6.jar
MD5: d63413e02885c25d0129e3d2936606f6
SHA1: 959c5d83d08f5cddf56caff749e48b735193191b
SHA256: d90bf1f8a9d2ba89f4510bb51e1516dcf94ef6dc034e00f233654abdd78f2210
Referenced In Project/Scope: waffle-jetty:provided
jetty-servlet-api-4.0.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.eclipse.jetty.ee8/jetty-ee8-apache-jsp@12.1.5
Evidence
Type Source Name Value Confidence
Vendor file name jetty-servlet-api High
Vendor jar package name servlet Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://eclipse.org/jetty Low
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-11 Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.servlet-api Medium
Vendor pom artifactid jetty-servlet-api Highest
Vendor pom artifactid jetty-servlet-api Low
Vendor pom groupid org.eclipse.jetty.toolchain Highest
Vendor pom name Jetty :: Servlet API and Schemas for JPMS and OSGi High
Vendor pom parent-artifactid jetty-toolchain Low
Product file name jetty-servlet-api High
Product jar package name servlet Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://eclipse.org/jetty Low
Product Manifest Bundle-Name Eclipse Jetty Servlet API and Schemas for JPMS and OSGi Medium
Product Manifest bundle-requiredexecutionenvironment JavaSE-11 Low
Product Manifest bundle-symbolicname org.eclipse.jetty.servlet-api Medium
Product pom artifactid jetty-servlet-api Highest
Product pom groupid org.eclipse.jetty.toolchain Highest
Product pom name Jetty :: Servlet API and Schemas for JPMS and OSGi High
Product pom parent-artifactid jetty-toolchain Medium
Version file version 4.0.6 High
Version Manifest Bundle-Version 4.0.6 High
Version pom parent-version 4.0.6 Low
Version pom version 4.0.6 Highest
pkg:maven/org.eclipse.jetty.toolchain/jetty-servlet-api@4.0.6
(Confidence :High)
jna-5.18.1.jar
Description:
Java Native Access
License:
LGPL-2.1-or-later: https://www.gnu.org/licenses/old-licenses/lgpl-2.1
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/net/java/dev/jna/jna/5.18.1/jna-5.18.1.jar
MD5: cb531ec131e1c68c045b5d45fe5b9878
SHA1: b27ba04287cc4abe769642fe8318d39fc89bf937
SHA256: 260c4b1e22b1db9e110ee441c4f13ce115f841fa48c41d78750986214b395557
Referenced In Project/Scope: waffle-jetty:compile
jna-5.18.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name jna High
Vendor jar package name jna Highest
Vendor jar package name native Highest
Vendor jar package name sun Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest automatic-module-name com.sun.jna Medium
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-category jni Low
Vendor Manifest bundle-nativecode com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win32, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win32, com/sun/jna/win32-aarch64/jnidispatch.dll; processor=aarch64;osname=win32, com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win, com/sun/jna/win32-aarch64/jnidispatch.dll; processor=aarch64;osname=win, com/sun/jna/w32ce-arm/jnidispatch.dll; processor=arm;osname=wince, com/sun/jna/sunos-x86/libjnidispatch.so; processor=x86;osname=sunos, com/sun/jna/sunos-x86-64/libjnidispatch.so; processor=x86-64;osname=sunos, com/sun/jna/sunos-sparc/libjnidispatch.so; processor=sparc;osname=sunos, com/sun/jna/sunos-sparcv9/libjnidispatch.so; processor=sparcv9;osname=sunos, com/sun/jna/aix-ppc/libjnidispatch.a; processor=ppc;osname=aix, com/sun/jna/aix-ppc64/libjnidispatch.a; processor=ppc64;osname=aix, com/sun/jna/linux-ppc/libjnidispatch.so; processor=ppc;osname=linux, com/sun/jna/linux-ppc64/libjnidispatch.so; processor=ppc64;osname=linux, com/sun/jna/linux-ppc64le/libjnidispatch.so; processor=ppc64le;osname=linux, com/sun/jna/linux-x86/libjnidispatch.so; processor=x86;osname=linux, com/sun/jna/linux-x86-64/libjnidispatch.so; processor=x86-64;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm_le;osname=linux, com/sun/jna/linux-armel/libjnidispatch.so; processor=armel;osname=linux, com/sun/jna/linux-aarch64/libjnidispatch.so; processor=aarch64;osname=linux, com/sun/jna/linux-ia64/libjnidispatch.so; processor=ia64;osname=linux, com/sun/jna/linux-sparcv9/libjnidispatch.so; processor=sparcv9;osname=linux, com/sun/jna/linux-mips64el/libjnidispatch.so; processor=mips64el;osname=linux, com/sun/jna/linux-s390x/libjnidispatch.so; processor=S390x;osname=linux, com/sun/jna/linux-loongarch64/libjnidispatch.so; processor=loongarch64;osname=linux, com/sun/jna/linux-riscv64/libjnidispatch.so; processor=riscv64;osname=linux, com/sun/jna/dragonflybsd-x86-64/libjnidispatch.so; processor=x86-64;osname=dragonflybsd, com/sun/jna/freebsd-x86/libjnidispatch.so; processor=x86;osname=freebsd, com/sun/jna/freebsd-x86-64/libjnidispatch.so; processor=x86-64;osname=freebsd, com/sun/jna/freebsd-aarch64/libjnidispatch.so; processor=aarch64;osname=freebsd, com/sun/jna/freebsd-ppc64le/libjnidispatch.so; processor=ppc64le;osname=freebsd, com/sun/jna/freebsd-ppc64/libjnidispatch.so; processor=ppc64;osname=freebsd, com/sun/jna/openbsd-x86/libjnidispatch.so; processor=x86;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=x86-64;osname=openbsd, com/sun/jna/darwin-ppc/libjnidispatch.jnilib; osname=macosx;processor=ppc, com/sun/jna/darwin-ppc64/libjnidispatch.jnilib; osname=macosx;processor=ppc64, com/sun/jna/darwin-x86/libjnidispatch.jnilib; osname=macosx;processor=x86, com/sun/jna/darwin-x86-64/libjnidispatch.jnilib; osname=macosx;processor=x86-64, com/sun/jna/darwin-aarch64/libjnidispatch.jnilib; osname=macosx;processor=aarch64 Low
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low
Vendor Manifest bundle-symbolicname com.sun.jna Medium
Vendor Manifest Implementation-Vendor JNA Development Team High
Vendor Manifest specification-vendor JNA Development Team Low
Vendor pom artifactid jna Highest
Vendor pom artifactid jna Low
Vendor pom developer email mblaesing@doppel-helix.eu Low
Vendor pom developer id twall Medium
Vendor pom developer name Matthias Bläsing Medium
Vendor pom developer name Timothy Wall Medium
Vendor pom groupid net.java.dev.jna Highest
Vendor pom name Java Native Access High
Vendor pom url java-native-access/jna Highest
Product file name jna High
Product jar package name jna Highest
Product jar package name library Highest
Product jar package name native Highest
Product jar package name sun Highest
Product jar package name win32 Highest
Product Manifest automatic-module-name com.sun.jna Medium
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-category jni Low
Product Manifest Bundle-Name jna Medium
Product Manifest bundle-nativecode com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win32, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win32, com/sun/jna/win32-aarch64/jnidispatch.dll; processor=aarch64;osname=win32, com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win, com/sun/jna/win32-aarch64/jnidispatch.dll; processor=aarch64;osname=win, com/sun/jna/w32ce-arm/jnidispatch.dll; processor=arm;osname=wince, com/sun/jna/sunos-x86/libjnidispatch.so; processor=x86;osname=sunos, com/sun/jna/sunos-x86-64/libjnidispatch.so; processor=x86-64;osname=sunos, com/sun/jna/sunos-sparc/libjnidispatch.so; processor=sparc;osname=sunos, com/sun/jna/sunos-sparcv9/libjnidispatch.so; processor=sparcv9;osname=sunos, com/sun/jna/aix-ppc/libjnidispatch.a; processor=ppc;osname=aix, com/sun/jna/aix-ppc64/libjnidispatch.a; processor=ppc64;osname=aix, com/sun/jna/linux-ppc/libjnidispatch.so; processor=ppc;osname=linux, com/sun/jna/linux-ppc64/libjnidispatch.so; processor=ppc64;osname=linux, com/sun/jna/linux-ppc64le/libjnidispatch.so; processor=ppc64le;osname=linux, com/sun/jna/linux-x86/libjnidispatch.so; processor=x86;osname=linux, com/sun/jna/linux-x86-64/libjnidispatch.so; processor=x86-64;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm_le;osname=linux, com/sun/jna/linux-armel/libjnidispatch.so; processor=armel;osname=linux, com/sun/jna/linux-aarch64/libjnidispatch.so; processor=aarch64;osname=linux, com/sun/jna/linux-ia64/libjnidispatch.so; processor=ia64;osname=linux, com/sun/jna/linux-sparcv9/libjnidispatch.so; processor=sparcv9;osname=linux, com/sun/jna/linux-mips64el/libjnidispatch.so; processor=mips64el;osname=linux, com/sun/jna/linux-s390x/libjnidispatch.so; processor=S390x;osname=linux, com/sun/jna/linux-loongarch64/libjnidispatch.so; processor=loongarch64;osname=linux, com/sun/jna/linux-riscv64/libjnidispatch.so; processor=riscv64;osname=linux, com/sun/jna/dragonflybsd-x86-64/libjnidispatch.so; processor=x86-64;osname=dragonflybsd, com/sun/jna/freebsd-x86/libjnidispatch.so; processor=x86;osname=freebsd, com/sun/jna/freebsd-x86-64/libjnidispatch.so; processor=x86-64;osname=freebsd, com/sun/jna/freebsd-aarch64/libjnidispatch.so; processor=aarch64;osname=freebsd, com/sun/jna/freebsd-ppc64le/libjnidispatch.so; processor=ppc64le;osname=freebsd, com/sun/jna/freebsd-ppc64/libjnidispatch.so; processor=ppc64;osname=freebsd, com/sun/jna/openbsd-x86/libjnidispatch.so; processor=x86;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=x86-64;osname=openbsd, com/sun/jna/darwin-ppc/libjnidispatch.jnilib; osname=macosx;processor=ppc, com/sun/jna/darwin-ppc64/libjnidispatch.jnilib; osname=macosx;processor=ppc64, com/sun/jna/darwin-x86/libjnidispatch.jnilib; osname=macosx;processor=x86, com/sun/jna/darwin-x86-64/libjnidispatch.jnilib; osname=macosx;processor=x86-64, com/sun/jna/darwin-aarch64/libjnidispatch.jnilib; osname=macosx;processor=aarch64 Low
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low
Product Manifest bundle-symbolicname com.sun.jna Medium
Product Manifest Implementation-Title com.sun.jna High
Product Manifest specification-title Java Native Access (JNA) Medium
Product pom artifactid jna Highest
Product pom developer email mblaesing@doppel-helix.eu Low
Product pom developer id twall Low
Product pom developer name Matthias Bläsing Low
Product pom developer name Timothy Wall Low
Product pom groupid net.java.dev.jna Highest
Product pom name Java Native Access High
Product pom url java-native-access/jna High
Version file version 5.18.1 High
Version Manifest Bundle-Version 5.18.1 High
Version pom version 5.18.1 Highest
pkg:maven/net.java.dev.jna/jna@5.18.1
(Confidence :High)
cpe:2.3:a:oracle:java_se:5.18.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jna-5.18.1.jar: jnidispatch.dll
File Path: /home/runner/.m2/repository/net/java/dev/jna/jna/5.18.1/jna-5.18.1.jar/com/sun/jna/win32-aarch64/jnidispatch.dll
MD5: 302945a811fd8e21bcdd5226c73b6f74
SHA1: 6b05e299ff2b3eb3b7b7aeac44263f715693607c
SHA256: b8f98be314234cf12b5b46c29652f70c0f6abb93ae19b63d3fe2692062aa699d
Referenced In Project/Scope: waffle-jetty:compile
Evidence
Type Source Name Value Confidence
Vendor file name jnidispatch High
Product file name jnidispatch High
jna-5.18.1.jar: jnidispatch.dll
File Path: /home/runner/.m2/repository/net/java/dev/jna/jna/5.18.1/jna-5.18.1.jar/com/sun/jna/win32-x86-64/jnidispatch.dll
MD5: 2d2475f1f026dd54e9f3e787ae4f81da
SHA1: 27ff882ac271db547aee520b38e3ba9aa91e136c
SHA256: 5a7ff949f6d93d86491eb5b26b1cfc60051168a60622650224b89995ac420023
Referenced In Project/Scope: waffle-jetty:compile
Evidence
Type Source Name Value Confidence
Vendor file name jnidispatch High
Product file name jnidispatch High
jna-5.18.1.jar: jnidispatch.dll
File Path: /home/runner/.m2/repository/net/java/dev/jna/jna/5.18.1/jna-5.18.1.jar/com/sun/jna/win32-x86/jnidispatch.dll
MD5: 0caa1ef75a807f9dde05084fa2219a5c
SHA1: 2f5e1cd82cde192905c7510ce99037b67d980640
SHA256: 752d597cee7e95cb517327146bf42f124c0d6c0bc48b3ecc3b1b3b0531a52f44
Referenced In Project/Scope: waffle-jetty:compile
Evidence
Type Source Name Value Confidence
Vendor file name jnidispatch High
Product file name jnidispatch High
jna-platform-5.18.1.jar
Description:
Java Native Access Platform
License:
LGPL-2.1-or-later: https://www.gnu.org/licenses/old-licenses/lgpl-2.1
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/net/java/dev/jna/jna-platform/5.18.1/jna-platform-5.18.1.jar
MD5: a7af00779ec98bfe22dfb07b1532830d
SHA1: dd817f391efc492041c9ae91127527c13750a789
SHA256: ad14c1b1ec4f43d396231219dfa635ebf828f738eac9f890ea1bc07795892d9a
Referenced In Project/Scope: waffle-jetty:compile
jna-platform-5.18.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name jna-platform High
Vendor jar package name jna Highest
Vendor jar package name platform Highest
Vendor jar package name sun Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest automatic-module-name com.sun.jna.platform Medium
Vendor Manifest bundle-category jni Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low
Vendor Manifest bundle-symbolicname com.sun.jna.platform Medium
Vendor Manifest Implementation-Vendor JNA Development Team High
Vendor Manifest specification-vendor JNA Development Team Low
Vendor pom artifactid jna-platform Highest
Vendor pom artifactid jna-platform Low
Vendor pom developer email mblaesing@doppel-helix.eu Low
Vendor pom developer id twall Medium
Vendor pom developer name Matthias Bläsing Medium
Vendor pom developer name Timothy Wall Medium
Vendor pom groupid net.java.dev.jna Highest
Vendor pom name Java Native Access Platform High
Vendor pom url java-native-access/jna Highest
Product file name jna-platform High
Product jar package name jna Highest
Product jar package name platform Highest
Product jar package name sun Highest
Product Manifest automatic-module-name com.sun.jna.platform Medium
Product Manifest bundle-category jni Low
Product Manifest Bundle-Name jna-platform Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low
Product Manifest bundle-symbolicname com.sun.jna.platform Medium
Product Manifest Implementation-Title com.sun.jna High
Product Manifest specification-title Java Native Access (JNA) Medium
Product pom artifactid jna-platform Highest
Product pom developer email mblaesing@doppel-helix.eu Low
Product pom developer id twall Low
Product pom developer name Matthias Bläsing Low
Product pom developer name Timothy Wall Low
Product pom groupid net.java.dev.jna Highest
Product pom name Java Native Access Platform High
Product pom url java-native-access/jna High
Version file version 5.18.1 High
Version Manifest Bundle-Version 5.18.1 High
Version pom version 5.18.1 Highest
pkg:maven/net.java.dev.jna/jna-platform@5.18.1
(Confidence :High)
jspecify-1.0.0.jar
Description:
An artifact of well-named and well-specified annotations to power static analysis checks
License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/jspecify/jspecify/1.0.0/jspecify-1.0.0.jar
MD5: 9133aba420d0ca3b001dbb6ae9992cf6
SHA1: 7425a601c1c7ec76645a78d22b8c6a627edee507
SHA256: 1fad6e6be7557781e4d33729d49ae1cdc8fdda6fe477bb0cc68ce351eafdfbab
Referenced In Project/Scope: waffle-jetty:compile
jspecify-1.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.junit.jupiter/junit-jupiter-engine@6.0.2
Evidence
Type Source Name Value Confidence
Vendor file name jspecify High
Vendor jar package name annotations Highest
Vendor jar package name jspecify Highest
Vendor Manifest bundle-docurl https://jspecify.dev/docs/start-here Low
Vendor Manifest bundle-symbolicname org.jspecify.jspecify Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid jspecify Highest
Vendor pom artifactid jspecify Low
Vendor pom developer email kevinb9n@gmail.com Low
Vendor pom developer id kevinb9n Medium
Vendor pom developer name Kevin Bourrillion Medium
Vendor pom groupid org.jspecify Highest
Vendor pom name JSpecify annotations High
Vendor pom url http://jspecify.org/ Highest
Product file name jspecify High
Product jar package name annotations Highest
Product jar package name jspecify Highest
Product Manifest bundle-docurl https://jspecify.dev/docs/start-here Low
Product Manifest Bundle-Name JSpecify annotations Medium
Product Manifest bundle-symbolicname org.jspecify.jspecify Medium
Product Manifest multi-release true Low
Product pom artifactid jspecify Highest
Product pom developer email kevinb9n@gmail.com Low
Product pom developer id kevinb9n Low
Product pom developer name Kevin Bourrillion Low
Product pom groupid org.jspecify Highest
Product pom name JSpecify annotations High
Product pom url http://jspecify.org/ Medium
Version file version 1.0.0 High
Version Manifest Bundle-Version 1.0.0 High
Version Manifest Implementation-Version 1.0.0 High
Version pom version 1.0.0 Highest
pkg:maven/org.jspecify/jspecify@1.0.0
(Confidence :High)
jsr305-3.0.2.jar
Description:
JSR305 Annotations for Findbugs
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/google/code/findbugs/jsr305/3.0.2/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256: 766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7
Referenced In Project/Scope: waffle-jetty:provided
jsr305-3.0.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8
Evidence
Type Source Name Value Confidence
Vendor file name jsr305 High
Vendor Manifest bundle-symbolicname org.jsr-305 Medium
Vendor pom artifactid jsr305 Highest
Vendor pom artifactid jsr305 Low
Vendor pom groupid com.google.code.findbugs Highest
Vendor pom name FindBugs-jsr305 High
Vendor pom url http://findbugs.sourceforge.net/ Highest
Product file name jsr305 High
Product Manifest Bundle-Name FindBugs-jsr305 Medium
Product Manifest bundle-symbolicname org.jsr-305 Medium
Product pom artifactid jsr305 Highest
Product pom groupid com.google.code.findbugs Highest
Product pom name FindBugs-jsr305 High
Product pom url http://findbugs.sourceforge.net/ Medium
Version file version 3.0.2 High
Version Manifest Bundle-Version 3.0.2 High
Version pom version 3.0.2 Highest
pkg:maven/com.google.code.findbugs/jsr305@3.0.2
(Confidence :High)
mortbay-apache-el-9.0.111.jar
Description:
A rebundling of Apache Tomcat Jasper to remove the tomcat server dependencies, so that the JSP engine can be used by the Eclipse Jetty project.
License:
http://www.apache.org/licenses/LICENSE-2.0
File Path: /home/runner/.m2/repository/org/mortbay/jasper/mortbay-apache-el/9.0.111/mortbay-apache-el-9.0.111.jar
MD5: 2b45155ffc38a4fe5d79ec6b4faafc32
SHA1: c374c62a07578442e4a649c8a5d01cac082685bf
SHA256: c1773366f32e50addf14f6fb1ea4da28547f0373389e093883664d36ec5e83a1
Referenced In Project/Scope: waffle-jetty:provided
mortbay-apache-el-9.0.111.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.eclipse.jetty.ee8/jetty-ee8-apache-jsp@12.1.5
Evidence
Type Source Name Value Confidence
Vendor file name mortbay-apache-el High
Vendor jar package name apache Highest
Vendor jar package name el Highest
Vendor Manifest automatic-module-name org.mortbay.apache.el Medium
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-docurl https://eclipse.dev/jetty/ Low
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Vendor Manifest bundle-symbolicname org.mortbay.jasper.mortbay-apache-el Medium
Vendor Manifest Implementation-Vendor Eclipse.org - Jetty High
Vendor Manifest url http://www.eclipse.org/jetty Low
Vendor pom artifactid mortbay-apache-el Highest
Vendor pom artifactid mortbay-apache-el Low
Vendor pom groupid org.mortbay.jasper Highest
Vendor pom name MortBay :: Apache EL :: API and Implementation High
Vendor pom parent-artifactid jasper-jsp Low
Product file name mortbay-apache-el High
Product jar package name apache Highest
Product jar package name el Highest
Product Manifest automatic-module-name org.mortbay.apache.el Medium
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-docurl https://eclipse.dev/jetty/ Low
Product Manifest Bundle-Name Mortbay Apache EL API and Implementation Medium
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Product Manifest bundle-symbolicname org.mortbay.jasper.mortbay-apache-el Medium
Product Manifest url http://www.eclipse.org/jetty Low
Product pom artifactid mortbay-apache-el Highest
Product pom groupid org.mortbay.jasper Highest
Product pom name MortBay :: Apache EL :: API and Implementation High
Product pom parent-artifactid jasper-jsp Medium
Version file version 9.0.111 High
Version Manifest Bundle-Version 9.0.111 High
Version Manifest Implementation-Version 9.0.111 High
Version pom version 9.0.111 Highest
pkg:maven/org.mortbay.jasper/mortbay-apache-el@9.0.111
(Confidence :High)
cpe:2.3:a:eclipse:jetty:9.0.111:*:*:*:*:*:*:*
(Confidence :Low)
suppress
cpe:2.3:a:jetty:jetty:9.0.111:*:*:*:*:*:*:*
(Confidence :Low)
suppress
cpe:2.3:a:mortbay:jetty:9.0.111:*:*:*:*:*:*:*
(Confidence :Low)
suppress
cpe:2.3:a:mortbay_jetty:jetty:9.0.111:*:*:*:*:*:*:*
(Confidence :Low)
suppress
CVE-2017-7657 suppress
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body could be interpreted as a pipelined request. If Jetty was deployed behind an intermediary that imposed some authorization and that intermediary allowed arbitrarily large chunks to be passed on unchanged, then this flaw could be used to bypass the authorization imposed by the intermediary as the fake pipelined request would not be interpreted by the intermediary as a request.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: HIGH (7.5)
Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P
References:
Vulnerable Software & Versions: (show all )
CVE-2017-7658 suppress
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decided on the shorter length, but still passed on the longer body, then body content could be interpreted by Jetty as a pipelined request. If the intermediary was imposing authorization, the fake pipelined request would bypass that authorization.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: HIGH (7.5)
Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P
References:
Vulnerable Software & Versions: (show all )
CVE-2017-7656 suppress
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9 is handled poorly. An HTTP/1 style request line (i.e. method space URI space version) that declares a version of HTTP/0.9 was accepted and treated as a 0.9 request. If deployed behind an intermediary that also accepted and passed through the 0.9 version (but did not act on it), then the response sent could be interpreted by the intermediary as HTTP/1 headers. This could be used to poison the cache if the server allowed the origin client to generate arbitrary content in the response.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), NVD-CWE-noinfo
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (5.0)
Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N
References:
Vulnerable Software & Versions: (show all )
CVE-2017-9735 suppress
Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
CWE-203 Observable Discrepancy
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (5.0)
Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N
References:
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/36870f6c51f5bc25e6f7bb1fcace0e57e81f1524019b11f466738559%40%3Ccommon-dev.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/f887a5978f5e4c62b9cfe876336628385cff429e796962649649ec8a%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY
cve@mitre.org - https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/36870f6c51f5bc25e6f7bb1fcace0e57e81f1524019b11f466738559%40%3Ccommon-dev.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/f887a5978f5e4c62b9cfe876336628385cff429e796962649649ec8a%40%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - ISSUE_TRACKING,MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - PATCH,THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY,VDB_ENTRY
Vulnerable Software & Versions: (show all )
CVE-2021-28165 suppress
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
CWE-400 Uncontrolled Resource Consumption, CWE-755 Improper Handling of Exceptional Conditions, CWE-551 Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: HIGH (7.8)
Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:C
References:
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r002258611ed0c35b82b839d284b43db9dcdec120db8afc1c993137dc%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r03ca0b69db1e3e5f72fe484b71370d537cd711cbf334e2913332730a%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r05db8e0ef01e1280cc7543575ae0fa1c2b4d06a8b928916ef65dd2ad%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r06d54a297cb8217c66e5190912a955fb870ba47da164002bf2baffe5%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r077b76cafb61520c14c87c4fc76419ed664002da0ddac5ad851ae7e7%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0841b06b48324cfc81325de3c05a92e53f997185f9d71ff47734d961%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0a241b0649beef90d422b42a26a2470d336e59e66970eafd54f9c3e2%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0a4797ba6ceea8074f47574a4f3cc11493d514c1fab8203ebd212add%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0bf3aa065abd23960fc8bdc8090d6bc00d5e391cf94ec4e1f4537ae3%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0cd1a5e3f4ad4770b44f8aa96572fc09d5b35bec149c0cc247579c42%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0f02034a33076fd7243cf3a8807d2766e373f5cb2e7fd0c9a78f97c4%40%3Cissues.hbase.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r111f1ce28b133a8090ca4f809a1bdf18a777426fc058dc3a16c39c66%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r17e26cf9a1e3cbc09522d15ece5d7c7a00cdced7641b92a22a783287%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r23785214d47673b811ef119ca3a40f729801865ea1e891572d15faa6%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2afc72af069a7fe89ca2de847f3ab3971cb1d668a9497c999946cd78%40%3Ccommits.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2ea2f0541121f17e470a0184843720046c59d4bde6d42bf5ca6fad81%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2f2d9c3b7cc750a6763d6388bcf5db0c7b467bd8be6ac4d6aea4f0cf%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r31f591a0deac927ede8ccc3eac4bb92697ee2361bf01549f9e3440ca%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r33eb3889ca0aa12720355e64fc2f8f1e8c0c28a4d55b3b4b8891becb%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r40136c2010fccf4fb2818a965e5d7ecca470e5f525c232ec5b8eb83a%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r401b1c592f295b811608010a70792b11c91885b72af9f9410cffbe35%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r411d75dc6bcefadaaea246549dd18e8d391a880ddf28a796f09ce152%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r47a7542ab61da865fff3db0fe74bfe76c89a37b6e6d2c2a423f8baee%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4891d45625cc522fe0eb764ac50d48bcca9c0db4805ea4a998d4c225%40%3Cissues.hbase.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4a66bfbf62281e31bc1345ebecbfd96f35199eecd77bfe4e903e906f%40%3Cissues.ignite.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4abbd760d24bab2b8f1294c5c9216ae915100099c4391ad64e9ae38b%40%3Cdev.hbase.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4b1fef117bccc7f5fd4c45fd2cabc26838df823fe5ca94bc42a4fd46%40%3Cissues.ignite.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r520c56519b8820955a86966f499e7a0afcbcf669d6f7da59ef1eb155%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r56e5568ac73daedcb3b5affbb4b908999f03d3c1b1ada3920b01e959%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5b3693da7ecb8a75c0e930b4ca26a5f97aa0207d9dae4aa8cc65fe6b%40%3Cissues.ignite.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5d1f16dca2e010193840068f1a1ec17b7015e91acc646607cbc0a4da%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5f172f2dd8fb02f032ef4437218fd4f610605a3dd4f2a024c1e43b94%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r64ff94118f6c80e6c085c6e2d51bbb490eaefad0642db8c936e4f0b7%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6535b2beddf0ed2d263ab64ff365a5f790df135a1a2f45786417adb7%40%3Cdev.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r65daad30d13f7c56eb5c3d7733ad8dddbf62c469175410777a78d812%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r694e57d74fcaa48818a03c282aecfa13ae68340c798dfcb55cb7acc7%40%3Cdev.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6ac9e263129328c0db9940d72b4a6062e703c58918dd34bd22cdf8dd%40%3Cissues.ignite.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6b070441871a4e6ce8bb63e190c879bb60da7c5e15023de29ebd4f9f%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6ce2907b2691c025250ba010bc797677ef78d5994d08507a2e5477c9%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6f256a1d15505f79f4050a69bb8f27b34cb353604dd2f765c9da5df7%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r71031d0acb1de55c9ab32f4750c50ce2f28543252e887ca03bd5621e%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r7189bf41cb0c483629917a01cf296f9fbdbda3987084595192e3845d%40%3Cissues.hbase.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r72bf813ed4737196ea3ed26494e949577be587fd5939fe8be09907c7%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r746434be6abff9ad321ff54ecae09e1f09c1c7c139021f40a5774090%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r769155244ca2da2948a44091bb3bb9a56e7e1c71ecc720b8ecf281f0%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r780c3c210a05c5bf7b4671303f46afc3fe56758e92864e1a5f0590d0%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r7bf7004c18c914fae3d5a6a0191d477e5b6408d95669b3afbf6efa36%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r7c40fb3a66a39b6e6c83b0454bc6917ffe6c69e3131322be9c07a1da%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r81748d56923882543f5be456043c67daef84d631cf54899082058ef1%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r83453ec252af729996476e5839d0b28f07294959d60fea1bd76f7d81%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r90327f55db8f1d079f9a724aabf1f5eb3c00c1de49dc7fd04cad1ebc%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r940f15db77a96f6aea92d830bc94d8d95f26cc593394d144755824da%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r942f4a903d0abb25ac75c592e57df98dea51350e8589269a72fd7913%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9974f64723875052e02787b2a5eda689ac5247c71b827d455e5dc9a6%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9b793db9f395b546e66fb9c44fe1cd75c7755029e944dfee31b8b779%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9db72e9c33b93eba45a214af588f1d553839b5c3080fc913854a49ab%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9fae5a4087d9ed1c9d4f0c7493b6981a4741cfb4bebb2416da638424%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra210e38ae0bf615084390b26ba01bb5d66c0a76f232277446ae0948a%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra21b3e6bd9669377139fe33fb46edf6fece3f31375bc42a0dcc964b2%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra50519652b0b7f869a14fbfb4be9758a29171d7fe561bb7e036e8449%40%3Cissues.hbase.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra9dd15ba8a4fb7e42c7fe948a6d6b3868fd6bbf8e3fb37fcf33b2cd0%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rae8bbc5a516f3e21b8a55e61ff6ad0ced03bdbd116d2170a3eed9f5c%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/raea6e820644e8c5a577f77d4e2044f8ab52183c2536b00c56738beef%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb00345f6b1620b553d2cc1acaf3017aa75cea3776b911e024fa3b187%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb11a13e623218c70b9f2a2d0d122fdaaf905e04a2edcd23761894464%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb1624b9777a3070135e94331a428c6653a6a1edccd56fa9fb7a547f2%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb2d34abb67cdf525945fe4b821c5cdbca29a78d586ae1f9f505a311c%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb66ed0b4bb74836add60dd5ddf9172016380b2aeefb7f96fe348537b%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb8f5a6ded384eb00608e6137e87110e7dd7d5054cc34561cb89b81af%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rbab9e67ec97591d063905bc7d4743e6a673f1bc457975fc0445ac97f%40%3Cissues.hbase.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rbba0b02a3287e34af328070dd58f7828612f96e2e64992137f4dc63d%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rbc075a4ac85e7a8e47420b7383f16ffa0af3b792b8423584735f369f%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rbcd7b477df55857bb6cae21fcc4404683ac98aac1a47551f0dc55486%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rbd9a837a18ca57ac0d9b4165a6eec95ee132f55d025666fe41099f33%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc4779abc1cface47e956cf9f8910f15d79c24477e7b1ac9be076a825%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc4dbc9907b0bdd634200ac90a15283d9c143c11af66e7ec72128d020%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc6c43c3180c0efe00497c73dd374cd34b62036cb67987ad42c1f2dce%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc907ed7b089828364437de5ed57fa062330970dc1bc5cd214b711f77%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rcdea97f4d3233298296aabc103c9fcefbf629425418c2b69bb16745f%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd0471252aeb3384c3cfa6d131374646d4641b80dd313e7b476c47a9c%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd24d8a059233167b4a5aebda4b3534ca1d86caa8a85b10a73403ee97%40%3Ccommits.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd6c1eb9a8a94b3ac8a525d74d792924e8469f201b77e1afcf774e7a6%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd755dfe5f658c42704540ad7950cebd136739089c3231658e398cf38%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd7c8fb305a8637480dc943ba08424c8992dccad018cd1405eb2afe0e%40%3Cdev.ignite.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd9ea411a58925cc82c32e15f541ead23cb25b4b2d57a2bdb0341536e%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdbf2a2cd1800540ae50dd78b57411229223a6172117d62b8e57596aa%40%3Cissues.hbase.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdde34d53aa80193cda016272d61e6749f8a9044ccb37a30768938f7e%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdf4fe435891e8c35e70ea5da033b4c3da78760f15a8c4212fad89d9f%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdfe5f1c071ba9dadba18d7fb0ff13ea6ecb33da624250c559999eaeb%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re0545ecced2d468c94ce4dcfa37d40a9573cc68ef5f6839ffca9c1c1%40%3Ccommits.hbase.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re3a1617d16a7367f767b8209b2151f4c19958196354b39568c532f26%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re577736ca7da51952c910b345a500b7676ea9931c9b19709b87f292b%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re6614b4fe7dbb945409daadb9e1cc73c02383df68bf9334736107a6e%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ree1895a256a9db951e0d97a76222909c2e1f28c1a3d89933173deed6%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf1b02dfccd27b8bbc3afd119b212452fa32e9ed7d506be9357a3a7ec%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf6de4c249bd74007f5f66f683c110535f46e719d2f83a41e8faf295f%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf99f9a25ca24fe519c9346388f61b5b3a09be31b800bf37f01473ad7%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rfc9f51b4e21022b3cd6cb6f90791a6a6999560212e519b5f09db0aed%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rfd3ff6e66b6bbcfb2fefa9f5a20328937c0369b2e142e3e1c6774743%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - NOT_APPLICABLE,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
emo@eclipse.org - https://lists.apache.org/thread.html/r002258611ed0c35b82b839d284b43db9dcdec120db8afc1c993137dc%40%3Cnotifications.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r03ca0b69db1e3e5f72fe484b71370d537cd711cbf334e2913332730a%40%3Cissues.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r05db8e0ef01e1280cc7543575ae0fa1c2b4d06a8b928916ef65dd2ad%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r06d54a297cb8217c66e5190912a955fb870ba47da164002bf2baffe5%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r077b76cafb61520c14c87c4fc76419ed664002da0ddac5ad851ae7e7%40%3Cjira.kafka.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r0841b06b48324cfc81325de3c05a92e53f997185f9d71ff47734d961%40%3Cissues.solr.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r0a241b0649beef90d422b42a26a2470d336e59e66970eafd54f9c3e2%40%3Ccommits.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r0a4797ba6ceea8074f47574a4f3cc11493d514c1fab8203ebd212add%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r0bf3aa065abd23960fc8bdc8090d6bc00d5e391cf94ec4e1f4537ae3%40%3Cjira.kafka.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r0cd1a5e3f4ad4770b44f8aa96572fc09d5b35bec149c0cc247579c42%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r0f02034a33076fd7243cf3a8807d2766e373f5cb2e7fd0c9a78f97c4%40%3Cissues.hbase.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r111f1ce28b133a8090ca4f809a1bdf18a777426fc058dc3a16c39c66%40%3Cissues.solr.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r17e26cf9a1e3cbc09522d15ece5d7c7a00cdced7641b92a22a783287%40%3Cissues.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r23785214d47673b811ef119ca3a40f729801865ea1e891572d15faa6%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r2afc72af069a7fe89ca2de847f3ab3971cb1d668a9497c999946cd78%40%3Ccommits.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r2ea2f0541121f17e470a0184843720046c59d4bde6d42bf5ca6fad81%40%3Cissues.solr.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r2f2d9c3b7cc750a6763d6388bcf5db0c7b467bd8be6ac4d6aea4f0cf%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r31f591a0deac927ede8ccc3eac4bb92697ee2361bf01549f9e3440ca%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r33eb3889ca0aa12720355e64fc2f8f1e8c0c28a4d55b3b4b8891becb%40%3Ccommits.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r40136c2010fccf4fb2818a965e5d7ecca470e5f525c232ec5b8eb83a%40%3Cjira.kafka.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r401b1c592f295b811608010a70792b11c91885b72af9f9410cffbe35%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r411d75dc6bcefadaaea246549dd18e8d391a880ddf28a796f09ce152%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r47a7542ab61da865fff3db0fe74bfe76c89a37b6e6d2c2a423f8baee%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r4891d45625cc522fe0eb764ac50d48bcca9c0db4805ea4a998d4c225%40%3Cissues.hbase.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r4a66bfbf62281e31bc1345ebecbfd96f35199eecd77bfe4e903e906f%40%3Cissues.ignite.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r4abbd760d24bab2b8f1294c5c9216ae915100099c4391ad64e9ae38b%40%3Cdev.hbase.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r4b1fef117bccc7f5fd4c45fd2cabc26838df823fe5ca94bc42a4fd46%40%3Cissues.ignite.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r520c56519b8820955a86966f499e7a0afcbcf669d6f7da59ef1eb155%40%3Ccommits.pulsar.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r56e5568ac73daedcb3b5affbb4b908999f03d3c1b1ada3920b01e959%40%3Cdev.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r5b3693da7ecb8a75c0e930b4ca26a5f97aa0207d9dae4aa8cc65fe6b%40%3Cissues.ignite.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r5d1f16dca2e010193840068f1a1ec17b7015e91acc646607cbc0a4da%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r5f172f2dd8fb02f032ef4437218fd4f610605a3dd4f2a024c1e43b94%40%3Cissues.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r64ff94118f6c80e6c085c6e2d51bbb490eaefad0642db8c936e4f0b7%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r6535b2beddf0ed2d263ab64ff365a5f790df135a1a2f45786417adb7%40%3Cdev.kafka.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r65daad30d13f7c56eb5c3d7733ad8dddbf62c469175410777a78d812%40%3Cjira.kafka.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r694e57d74fcaa48818a03c282aecfa13ae68340c798dfcb55cb7acc7%40%3Cdev.kafka.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r6ac9e263129328c0db9940d72b4a6062e703c58918dd34bd22cdf8dd%40%3Cissues.ignite.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r6b070441871a4e6ce8bb63e190c879bb60da7c5e15023de29ebd4f9f%40%3Cjira.kafka.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r6ce2907b2691c025250ba010bc797677ef78d5994d08507a2e5477c9%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r6f256a1d15505f79f4050a69bb8f27b34cb353604dd2f765c9da5df7%40%3Cjira.kafka.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r71031d0acb1de55c9ab32f4750c50ce2f28543252e887ca03bd5621e%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r7189bf41cb0c483629917a01cf296f9fbdbda3987084595192e3845d%40%3Cissues.hbase.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r72bf813ed4737196ea3ed26494e949577be587fd5939fe8be09907c7%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r746434be6abff9ad321ff54ecae09e1f09c1c7c139021f40a5774090%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r769155244ca2da2948a44091bb3bb9a56e7e1c71ecc720b8ecf281f0%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r780c3c210a05c5bf7b4671303f46afc3fe56758e92864e1a5f0590d0%40%3Cjira.kafka.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r7bf7004c18c914fae3d5a6a0191d477e5b6408d95669b3afbf6efa36%40%3Ccommits.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r7c40fb3a66a39b6e6c83b0454bc6917ffe6c69e3131322be9c07a1da%40%3Cissues.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r81748d56923882543f5be456043c67daef84d631cf54899082058ef1%40%3Cjira.kafka.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r83453ec252af729996476e5839d0b28f07294959d60fea1bd76f7d81%40%3Cissues.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r90327f55db8f1d079f9a724aabf1f5eb3c00c1de49dc7fd04cad1ebc%40%3Ccommits.pulsar.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r940f15db77a96f6aea92d830bc94d8d95f26cc593394d144755824da%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r942f4a903d0abb25ac75c592e57df98dea51350e8589269a72fd7913%40%3Cissues.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r9974f64723875052e02787b2a5eda689ac5247c71b827d455e5dc9a6%40%3Cissues.solr.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r9b793db9f395b546e66fb9c44fe1cd75c7755029e944dfee31b8b779%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r9db72e9c33b93eba45a214af588f1d553839b5c3080fc913854a49ab%40%3Cnotifications.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r9fae5a4087d9ed1c9d4f0c7493b6981a4741cfb4bebb2416da638424%40%3Cissues.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/ra210e38ae0bf615084390b26ba01bb5d66c0a76f232277446ae0948a%40%3Cnotifications.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/ra21b3e6bd9669377139fe33fb46edf6fece3f31375bc42a0dcc964b2%40%3Cnotifications.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/ra50519652b0b7f869a14fbfb4be9758a29171d7fe561bb7e036e8449%40%3Cissues.hbase.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/ra9dd15ba8a4fb7e42c7fe948a6d6b3868fd6bbf8e3fb37fcf33b2cd0%40%3Cnotifications.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rae8bbc5a516f3e21b8a55e61ff6ad0ced03bdbd116d2170a3eed9f5c%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/raea6e820644e8c5a577f77d4e2044f8ab52183c2536b00c56738beef%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rb00345f6b1620b553d2cc1acaf3017aa75cea3776b911e024fa3b187%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rb11a13e623218c70b9f2a2d0d122fdaaf905e04a2edcd23761894464%40%3Cnotifications.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rb1624b9777a3070135e94331a428c6653a6a1edccd56fa9fb7a547f2%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rb2d34abb67cdf525945fe4b821c5cdbca29a78d586ae1f9f505a311c%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rb66ed0b4bb74836add60dd5ddf9172016380b2aeefb7f96fe348537b%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rb8f5a6ded384eb00608e6137e87110e7dd7d5054cc34561cb89b81af%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rbab9e67ec97591d063905bc7d4743e6a673f1bc457975fc0445ac97f%40%3Cissues.hbase.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rbba0b02a3287e34af328070dd58f7828612f96e2e64992137f4dc63d%40%3Cnotifications.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rbc075a4ac85e7a8e47420b7383f16ffa0af3b792b8423584735f369f%40%3Cissues.solr.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rbcd7b477df55857bb6cae21fcc4404683ac98aac1a47551f0dc55486%40%3Cissues.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rbd9a837a18ca57ac0d9b4165a6eec95ee132f55d025666fe41099f33%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rc4779abc1cface47e956cf9f8910f15d79c24477e7b1ac9be076a825%40%3Cjira.kafka.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rc4dbc9907b0bdd634200ac90a15283d9c143c11af66e7ec72128d020%40%3Cjira.kafka.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rc6c43c3180c0efe00497c73dd374cd34b62036cb67987ad42c1f2dce%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rc907ed7b089828364437de5ed57fa062330970dc1bc5cd214b711f77%40%3Ccommits.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rcdea97f4d3233298296aabc103c9fcefbf629425418c2b69bb16745f%40%3Ccommits.pulsar.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rd0471252aeb3384c3cfa6d131374646d4641b80dd313e7b476c47a9c%40%3Cissues.solr.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rd24d8a059233167b4a5aebda4b3534ca1d86caa8a85b10a73403ee97%40%3Ccommits.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rd6c1eb9a8a94b3ac8a525d74d792924e8469f201b77e1afcf774e7a6%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rd755dfe5f658c42704540ad7950cebd136739089c3231658e398cf38%40%3Cjira.kafka.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rd7c8fb305a8637480dc943ba08424c8992dccad018cd1405eb2afe0e%40%3Cdev.ignite.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rd9ea411a58925cc82c32e15f541ead23cb25b4b2d57a2bdb0341536e%40%3Cjira.kafka.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rdbf2a2cd1800540ae50dd78b57411229223a6172117d62b8e57596aa%40%3Cissues.hbase.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rdde34d53aa80193cda016272d61e6749f8a9044ccb37a30768938f7e%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rdf4fe435891e8c35e70ea5da033b4c3da78760f15a8c4212fad89d9f%40%3Ccommits.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rdfe5f1c071ba9dadba18d7fb0ff13ea6ecb33da624250c559999eaeb%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/re0545ecced2d468c94ce4dcfa37d40a9573cc68ef5f6839ffca9c1c1%40%3Ccommits.hbase.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/re3a1617d16a7367f767b8209b2151f4c19958196354b39568c532f26%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/re577736ca7da51952c910b345a500b7676ea9931c9b19709b87f292b%40%3Cissues.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/re6614b4fe7dbb945409daadb9e1cc73c02383df68bf9334736107a6e%40%3Cdev.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/ree1895a256a9db951e0d97a76222909c2e1f28c1a3d89933173deed6%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rf1b02dfccd27b8bbc3afd119b212452fa32e9ed7d506be9357a3a7ec%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rf6de4c249bd74007f5f66f683c110535f46e719d2f83a41e8faf295f%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rf99f9a25ca24fe519c9346388f61b5b3a09be31b800bf37f01473ad7%40%3Cnotifications.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rfc9f51b4e21022b3cd6cb6f90791a6a6999560212e519b5f09db0aed%40%3Ccommits.pulsar.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rfd3ff6e66b6bbcfb2fefa9f5a20328937c0369b2e142e3e1c6774743%40%3Creviews.spark.apache.org%3E
emo@eclipse.org - EXPLOIT,THIRD_PARTY_ADVISORY
emo@eclipse.org - MAILING_LIST,THIRD_PARTY_ADVISORY
emo@eclipse.org - MAILING_LIST,THIRD_PARTY_ADVISORY
emo@eclipse.org - NOT_APPLICABLE,THIRD_PARTY_ADVISORY
emo@eclipse.org - PATCH,THIRD_PARTY_ADVISORY
emo@eclipse.org - PATCH,THIRD_PARTY_ADVISORY
emo@eclipse.org - PATCH,THIRD_PARTY_ADVISORY
emo@eclipse.org - THIRD_PARTY_ADVISORY
Vulnerable Software & Versions: (show all )
CVE-2022-2048 suppress
In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests.
CWE-664 Improper Control of a Resource Through its Lifetime, NVD-CWE-Other, CWE-410 Insufficient Resource Pool
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (5.0)
Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P
References:
Vulnerable Software & Versions: (show all )
CVE-2023-44487 suppress
CISA Known Exploited Vulnerability:
Product: IETF HTTP/2
Name: HTTP/2 Rapid Reset Attack Vulnerability
Date Added: 2023-10-10
Description: HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due Date: 2023-10-31
Notes: This vulnerability affects a common open-source component, third-party library, or protocol used by different products. For more information, please see: HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487 | CISA: https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487; https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/; https://nvd.nist.gov/vuln/detail/CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CWE-400 Uncontrolled Resource Consumption, NVD-CWE-noinfo
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
134c704f-9b21-4f2e-91b3-4a467353bcc0 - US_GOVERNMENT_RESOURCE
af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,MITIGATION,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PRESS/MEDIA_COVERAGE
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,PATCH,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,RELEASE_NOTES,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MITIGATION,PATCH,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MITIGATION,PATCH,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MITIGATION,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH
af854a3a-2127-422b-91ae-364da2661108 - PATCH
af854a3a-2127-422b-91ae-364da2661108 - PATCH
af854a3a-2127-422b-91ae-364da2661108 - PATCH,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PRESS/MEDIA_COVERAGE
af854a3a-2127-422b-91ae-364da2661108 - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PRODUCT
af854a3a-2127-422b-91ae-364da2661108 - PRODUCT
af854a3a-2127-422b-91ae-364da2661108 - PRODUCT,RELEASE_NOTES
af854a3a-2127-422b-91ae-364da2661108 - PRODUCT,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,US_GOVERNMENT_RESOURCE
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
cve@mitre.org - BROKEN_LINK
cve@mitre.org - EXPLOIT,THIRD_PARTY_ADVISORY
cve@mitre.org - EXPLOIT,THIRD_PARTY_ADVISORY
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING,MITIGATION,VENDOR_ADVISORY
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PRESS/MEDIA_COVERAGE
cve@mitre.org - ISSUE_TRACKING,THIRD_PARTY_ADVISORY
cve@mitre.org - ISSUE_TRACKING,VENDOR_ADVISORY
cve@mitre.org - ISSUE_TRACKING,VENDOR_ADVISORY
cve@mitre.org - ISSUE_TRACKING,VENDOR_ADVISORY
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST,PATCH,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,PATCH,VENDOR_ADVISORY
cve@mitre.org - MAILING_LIST,RELEASE_NOTES,VENDOR_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,VENDOR_ADVISORY
cve@mitre.org - MAILING_LIST,VENDOR_ADVISORY
cve@mitre.org - MITIGATION,PATCH,VENDOR_ADVISORY
cve@mitre.org - MITIGATION,PATCH,VENDOR_ADVISORY
cve@mitre.org - MITIGATION,VENDOR_ADVISORY
cve@mitre.org - PATCH
cve@mitre.org - PATCH
cve@mitre.org - PATCH
cve@mitre.org - PATCH,VENDOR_ADVISORY
cve@mitre.org - PATCH,VENDOR_ADVISORY
cve@mitre.org - PRESS/MEDIA_COVERAGE
cve@mitre.org - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
cve@mitre.org - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
cve@mitre.org - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
cve@mitre.org - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
cve@mitre.org - PRODUCT
cve@mitre.org - PRODUCT
cve@mitre.org - PRODUCT,RELEASE_NOTES
cve@mitre.org - PRODUCT,THIRD_PARTY_ADVISORY
cve@mitre.org - RELEASE_NOTES
cve@mitre.org - RELEASE_NOTES
cve@mitre.org - RELEASE_NOTES,THIRD_PARTY_ADVISORY
cve@mitre.org - RELEASE_NOTES,VENDOR_ADVISORY
cve@mitre.org - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY
cve@mitre.org - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY
cve@mitre.org - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY,US_GOVERNMENT_RESOURCE
cve@mitre.org - THIRD_PARTY_ADVISORY,VENDOR_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY,VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
Vulnerable Software & Versions: (show all )
CVE-2024-9823 suppress
There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory finally.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2020-27216 suppress
In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to complete the creation of the temporary subdirectory. If the attacker wins the race then they will have read and write permission to the subdirectory used to unpack web applications, including their WEB-INF/lib jar files and JSP files. If any code is ever executed out of this temporary directory, this can lead to a local privilege escalation vulnerability.
CWE-378 Creation of Temporary File With Insecure Permissions, CWE-379 Creation of Temporary File in Directory with Insecure Permissions, NVD-CWE-Other
CVSSv3:
Base Score: HIGH (7.0)
Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.0/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (4.4)
Vector: /AV:L/AC:M/Au:N/C:P/I:P/A:P
References:
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0259b14ae69b87821e27fed1f5333ea86018294fd31aab16b1fac84e%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r07525dc424ed69b3919618599e762f9ac03791490ca9d724f2241442%40%3Cdev.felix.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r09b345099b4f88d2bed7f195a96145849243fb4e53661aa3bcf4c176%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0d7ad4f02c44d5d53a9ffcbca7ff4a8138241322da9c5c35b5429630%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0d95e01f52667f44835c40f6dea72bb4397f33cd70a564ea74f3836d%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0df8fe10fc36028cf6d0381ab66510917d0d68bc5ef7042001d03830%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0e9efe032cc65433251ee6470c66c334d4e7db9101e24cf91a3961f2%40%3Ccommits.directory.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0f5e9b93133ef3aaf31484bc3e15cc4b85f8af0fe4de2dacd9379d72%40%3Cdev.felix.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r100c5c7586a23a19fdb54d8a32e17cd0944bdaa46277b35c397056f6%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r171846414347ec5fed38241a9f8a009bd2c89d902154c6102b1fb39a%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r185d10aae8161c08726f3ba9a1f1c47dfb97624ea6212fa217173204%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r18b6f10d9939419bae9c225d5058c97533cb376c9d6d0a0733ddd48d%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r19e8b338af511641d211ff45c43646fe1ae19dc9897d69939c09cabe%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r1d40368a309f9d835dcdd900249966e4fcbdf98c1cc4c84db2cd9964%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r1d45051310b11c6d6476f20d71b08ea97cb76846cbf61d196bac1c3f%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r1dbb87c9255ecefadd8de514fa1d35c1d493c0527d7672cf40505d04%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r1ed79516bd6d248ea9f0e704dbfd7de740d5a75b71c7be8699fec824%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r1ef28b89ff0281c87ba3a7659058789bf28a99b8074191f1c3678db8%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r1fe31643fc34b4a33ae3d416d92c271aa97663f1782767d25e1d9ff8%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2122537d3f9beb0ce59f44371a951b226406719919656ed000984bd0%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r279254a1bd6434c943da52000476f307e62b6910755387aeca1ec9a1%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2aa316d008dab9ae48350b330d15dc1b863ea2a933558fbfc42b91a6%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2d17b2a4803096ba427f3575599ea29b55f5cf9dbc1f12ba044cae1a%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2e02700f7cfecb213de50be83e066086bea90278cd753db7fdc2ccff%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2f732ee49d00610683ab5ddb4692ab25136b00bfd132ca3a590218a9%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r3042a9dd2973aa229e52d022df7813e4d74b67df73bfa6d97bb0caf8%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r336b1694a01858111e4625fb9ab2b07ad43a64a525cf6402e06aa6bf%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r351298dd39fc1ab63303be94b0c0d08acd72b17448e0346d7386189b%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r352e40ca9874d1beb4ad95403792adca7eb295e6bc3bd7b65fabcc21%40%3Ccommits.samza.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r382870d6ccfd60533eb0d980688261723ed8a0704dafa691c4e9aa68%40%3Ccommits.iotdb.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r3a763de620be72b6d74f46ec4bf39c9f35f8a0b39993212c0ac778ec%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r3b0ce1549a1ccdd7e51ec66daf8d54d46f1571edbda88ed09c96d7da%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r3e05ab0922876e74fea975d70af82b98580f4c14ba643c4f8a9e3a94%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r3f32cb4965239399c22497a0aabb015b28b2372d4897185a6ef0ccd7%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r407c316f6113dfc76f7bb3cb1693f08274c521064a92e5214197548e%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4179c71908778cc0598ee8ee1eaed9b88fc5483c65373f45e087f650%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r44115ebfbf3b7d294d7a75f2d30bcc822dab186ebbcc2dce11915ca9%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4946ffd86ad6eb7cb7863311235c914cb41232380de8d9dcdb3c115c%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4f29fb24639ebc5d15fc477656ebc2b3aa00fcfbe197000009c26b40%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r503045a75f4419d083cb63ac89e765d6fb8b10c7dacc0c54fce07cff%40%3Creviews.iotdb.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r547bb14c88c5da2588d853ed3030be0109efa537dd797877dff14afd%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5494fdaf4a0a42a15c49841ba7ae577d466d09239ee1050458da0f29%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r556787f1ab14da034d79dfff0c123c05877bbe89ef163fd359b4564c%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r568d354961fa88f206dc345411fb11d245c6dc1a8da3e80187fc6706%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r58f5b14dc5ae43583db3a7e872419aca97ebe47bcd7f7334f4128016%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r59e0878013d329dcc481eeafebdb0ee445b1e2852d0c4827b1ddaff2%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5a07f274f355c914054c7357ad6d3456ffaca064f26cd780acb90a9a%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5a9462096c71593e771602beb0e69357adb5175d9a5c18d5181e0ab4%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6236ae4adc401e3b2f2575c22865f2f6c6ea9ff1d7b264b40d9602af%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r66e99d973fd79ddbcb3fbdb24f4767fe9b911f5b0abb05d7b6f65801%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6b83ca85c8f9a6794b1f85bc70d1385ed7bc1ad07750d0977537154a%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6dfa64ecc3d67c1a71c08bfa04064549179d499f8e20a8285c57bd51%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6f51a654ac2e67e3d1c65a8957cbbb127c3f15b64b4fcd626df03633%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r70f8bcccd304bd66c1aca657dbfc2bf11f73add9032571b01f1f733d%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r71da5f51ef04cb95abae560425dce9667740cbd567920f516f76efb7%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r73b5a9b677b707bbb7c1469ea746312c47838b312603bada9e382bba%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r761a52f1e214efec286ee80045d0012e955eebaa72395ad62cccbcfc%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r769411eb43dd9ef77665700deb7fc491fc3ceb532914260c90b56f2f%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r77dd041d8025a869156481d2268c67ad17121f64e31f9b4a1a220145%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r7bdc83513c12db1827b79b8d57a7a0975a25d28bc6c5efe590ec1e02%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r7da5ae60d7973e8894cfe92f49ecb5b47417eefab4c77cc87514d3cf%40%3Cdev.felix.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r8045eedd6bb74efcd8e01130796adbab98ee4a0d1273509fb1f2077a%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r819857361f5a156e90d6d06ccf6c41026bc99030d60d0804be3a9957%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r827d17bf6900eddc686f4b6ee16fc5e52ca0070f8df7612222c40ac5%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r874688141495df766e62be095f1dfb0bf4a24ca0340d8e0215c03fab%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r87b0c69fef09277333a7e1716926d1f237d462e143a335854ddd922f%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r87d8337300a635d66f0bb838bf635cdfcbba6b92c608a7813adbf4f4%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r8866f0cd2a3b319288b7eea20ac137b9f260c813d10ee2db88b65d32%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r8cacf91ae1b17cc6531d20953c52fa52f6fd3191deb3383446086ab7%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r8dd01541fc49d24ec223365a9974231cbd7378b749247a89b0a52210%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r8fead0144bb84d8714695c43607dca9c5101aa028a431ec695882fe5%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r90b5ac6e2bf190a5297bda58c7ec76d01cd86ff050b2470fcd9f4b35%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r911c1879258ebf98bca172c0673350eb7ea6569ca1735888d4cb7adc%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r916b6542bd5b15a8a7ff8fc14a0e0331e8e3e9d682f22768ae71d775%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r93b240be16e642579ed794325bae31b040e1af896ecc12466642e19d%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r93d5e81e879120d8d87925dbdd4045cb3afa9b066f4370f60b626ce3%40%3Ccommits.druid.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9b790fe3a93121199f41258474222f15002b2f729495aa7ecbf90718%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9c010b79140452294292379183e7fe8e3533c5bb4db3f3fb39a6df61%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9cc76b98f87738791b8ec3736755f92444d3c8cb26bd4e4ffdb5c1cc%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9cd444f944241dc26d9b8b007fe8971ed7f005b56befef7a4f4fb827%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9d9b4b93df7f92cdf1147db0fc169be1776c93d1fbc63bc65721fffd%40%3Cdev.knox.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9f8c45a2a4540911cd8bd0485f67e8091883c9234d7a3aeb349c46c1%40%3Creviews.iotdb.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra1f19625cc67ac1b459c558f2ea5647d71ce51c6fe4f4cb03baec849%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra55e04d5a73afcb8383f4386e2b26832c6e3972e53827021ab885943%40%3Ccommits.shiro.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra5b7313d8cc9411db6790adfba33f2cf0665cb77adb7b02043c95867%40%3Cdev.felix.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/raa9c370ab42d737e93bc1795bb6a2187d7c60210cd5e3b3ce8f3c484%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rad255c736fad46135f1339408cb0147d0671e45c376c3be85ceeec1a%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rae15d73cabef55bad148e4e6449b05da95646a2a8db3fc938e858dff%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/raf9c581b793c30ff8f55f2415c7bd337eb69775aae607bf9ed1b16fb%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rafb023a7c61180a1027819678eb2068b0b60cd5c2559cb8490e26c81%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb077d35f2940191daeefca0d6449cddb2e9d06bcf8f5af4da2df3ca2%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb5f2558ea2ac63633dfb04db1e8a6ea6bb1a2b8614899095e16c6233%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb69b1d7008a4b3de5ce5867e41a455693907026bc70ead06867aa323%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb7e159636b26156f6ef2b2a1a79b3ec9a026923b5456713e68f7c18e%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb81a018f83fe02c95a2138a7bb4f1e1677bd7e1fc1e7024280c2292d%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb8ad3745cb94c60d44cc369aff436eaf03dbc93112cefc86a2ed53ba%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb8c007f87dc57731a7b9a3b05364530422535b7e0bc6a0c5b68d4d55%40%3Cdev.felix.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rbc5a622401924fadab61e07393235838918228b3d8a1a6704295b032%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rbc5a8d7a0a13bc8152d427a7e9097cdeb139c6cfe111b2f00f26d16b%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rbf99e4495461099cad9aa62e0164f8f25a7f97b791b4ace56e375f8d%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc1646894341450fdc4f7e96a88f5e2cf18d8004714f98aec6b831b3e%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc1d9b8e9d17749d4d2b9abaaa72c422d090315bd6bc0ae73a16abc1c%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc2e24756d28580eeac811c5c6a12012c9f424b6e5bffb89f98ee3d03%40%3Cdev.felix.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc44d1147f78496ec9932a38b28795ff4fd0c4fa6e3b6f5cc33c14d29%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc4b972ea10c5a65c6a88a6e233778718ab9af7f484affdd5e5de0cff%40%3Ccommits.felix.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc77918636d8744d50312e4f67ba2e01f47db3ec5144540df8745cb38%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc8dd95802be0cca8d7d0929c0c8484ede384ecb966b2a9dc7197b089%40%3Creviews.iotdb.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc9d2ab8a6c7835182f20b01104798e67c75db655c869733a0713a590%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rccedec4cfd5df6761255b71349e3b7c27ee0745bd33698a71b1775cf%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rcdcf32952397c83a1d617a8c9cd5c15c98b8d0d38a607972956bde7e%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rcdd56ab4255801a0964dcce3285e87f2c6994e6469e189f6836f34e3%40%3Cnotifications.iotdb.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rcfb95a7c69c4b9c082ea1918e812dfc45aa0d1e120fd47f68251a336%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rcff5caebfd535195276aaabc1b631fd55a4ff6b14e2bdfe33f18ff91%40%3Creviews.iotdb.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd58b60ab2e49ebf21022e59e280feb25899ff785c88f31fe314aa5b9%40%3Ccommits.shiro.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd7e62e2972a41c2658f41a824b8bdd15644d80fcadc51fe7b7c855de%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdbf1cd0ab330c032f3a09b453cb6405dccc905ad53765323bddab957%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdddb4b06e86fd58a1beda132f22192af2f9b56aae8849cb3767ccd55%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rde11c433675143d8d27551c3d9e821fe1955f1551a518033d3716553%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rde782fd8e133f7e04e50c8aaa4774df524367764eb5b85bf60d96747%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re08b03cd1754b32f342664eead415af48092c630c8e3e0deba862a26%40%3Ccommits.shiro.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re5706141ca397587f7ee0f500a39ccc590a41f802fc125fc135cb92f%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ree506849c4f04376793b1a3076bc017da60b8a2ef2702dc214ff826f%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/refbbb0eb65c185d1fa491cee08ac8ed32708ce3b269133a6da264317%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf00ea6376f3d0e8b8f62cf6d4a4f28b24e27193acd2c851f618aa41e%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf3bc023a7cc729aeac72f482e2eeeab9008aa6b1dadbeb3f45320cae%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rfd9f102864a039f7fda64a580dfe1a342d65d7b723ca06dc9fbceb31%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rfe5caef1fd6cf4b8ceac1b63c33195f2908517b665c946c020d3fbd6%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rfe6ba83d14545e982400dea89e68b10113cb5202a3dcb558ce64842d%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rff0ad6a7dac2182421e2db2407e44fbb61a89904adfd91538f21fbf8%40%3Cissues.beam.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,MITIGATION,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,PATCH,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - NOT_APPLICABLE,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
emo@eclipse.org - https://lists.apache.org/thread.html/r0259b14ae69b87821e27fed1f5333ea86018294fd31aab16b1fac84e%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r07525dc424ed69b3919618599e762f9ac03791490ca9d724f2241442%40%3Cdev.felix.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r09b345099b4f88d2bed7f195a96145849243fb4e53661aa3bcf4c176%40%3Cissues.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r0d7ad4f02c44d5d53a9ffcbca7ff4a8138241322da9c5c35b5429630%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r0d95e01f52667f44835c40f6dea72bb4397f33cd70a564ea74f3836d%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r0df8fe10fc36028cf6d0381ab66510917d0d68bc5ef7042001d03830%40%3Cdev.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r0e9efe032cc65433251ee6470c66c334d4e7db9101e24cf91a3961f2%40%3Ccommits.directory.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r0f5e9b93133ef3aaf31484bc3e15cc4b85f8af0fe4de2dacd9379d72%40%3Cdev.felix.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r100c5c7586a23a19fdb54d8a32e17cd0944bdaa46277b35c397056f6%40%3Cnotifications.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r171846414347ec5fed38241a9f8a009bd2c89d902154c6102b1fb39a%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r185d10aae8161c08726f3ba9a1f1c47dfb97624ea6212fa217173204%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r18b6f10d9939419bae9c225d5058c97533cb376c9d6d0a0733ddd48d%40%3Cnotifications.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r19e8b338af511641d211ff45c43646fe1ae19dc9897d69939c09cabe%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r1d40368a309f9d835dcdd900249966e4fcbdf98c1cc4c84db2cd9964%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r1d45051310b11c6d6476f20d71b08ea97cb76846cbf61d196bac1c3f%40%3Cdev.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r1dbb87c9255ecefadd8de514fa1d35c1d493c0527d7672cf40505d04%40%3Ccommits.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r1ed79516bd6d248ea9f0e704dbfd7de740d5a75b71c7be8699fec824%40%3Cnotifications.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r1ef28b89ff0281c87ba3a7659058789bf28a99b8074191f1c3678db8%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r1fe31643fc34b4a33ae3d416d92c271aa97663f1782767d25e1d9ff8%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r2122537d3f9beb0ce59f44371a951b226406719919656ed000984bd0%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r279254a1bd6434c943da52000476f307e62b6910755387aeca1ec9a1%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r2aa316d008dab9ae48350b330d15dc1b863ea2a933558fbfc42b91a6%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r2d17b2a4803096ba427f3575599ea29b55f5cf9dbc1f12ba044cae1a%40%3Cnotifications.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r2e02700f7cfecb213de50be83e066086bea90278cd753db7fdc2ccff%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r2f732ee49d00610683ab5ddb4692ab25136b00bfd132ca3a590218a9%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r3042a9dd2973aa229e52d022df7813e4d74b67df73bfa6d97bb0caf8%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r336b1694a01858111e4625fb9ab2b07ad43a64a525cf6402e06aa6bf%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r351298dd39fc1ab63303be94b0c0d08acd72b17448e0346d7386189b%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r352e40ca9874d1beb4ad95403792adca7eb295e6bc3bd7b65fabcc21%40%3Ccommits.samza.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r382870d6ccfd60533eb0d980688261723ed8a0704dafa691c4e9aa68%40%3Ccommits.iotdb.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r3a763de620be72b6d74f46ec4bf39c9f35f8a0b39993212c0ac778ec%40%3Ccommits.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r3b0ce1549a1ccdd7e51ec66daf8d54d46f1571edbda88ed09c96d7da%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r3e05ab0922876e74fea975d70af82b98580f4c14ba643c4f8a9e3a94%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r3f32cb4965239399c22497a0aabb015b28b2372d4897185a6ef0ccd7%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r407c316f6113dfc76f7bb3cb1693f08274c521064a92e5214197548e%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r4179c71908778cc0598ee8ee1eaed9b88fc5483c65373f45e087f650%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r44115ebfbf3b7d294d7a75f2d30bcc822dab186ebbcc2dce11915ca9%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r4946ffd86ad6eb7cb7863311235c914cb41232380de8d9dcdb3c115c%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r4f29fb24639ebc5d15fc477656ebc2b3aa00fcfbe197000009c26b40%40%3Cissues.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r503045a75f4419d083cb63ac89e765d6fb8b10c7dacc0c54fce07cff%40%3Creviews.iotdb.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r547bb14c88c5da2588d853ed3030be0109efa537dd797877dff14afd%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r5494fdaf4a0a42a15c49841ba7ae577d466d09239ee1050458da0f29%40%3Cjira.kafka.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r556787f1ab14da034d79dfff0c123c05877bbe89ef163fd359b4564c%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r568d354961fa88f206dc345411fb11d245c6dc1a8da3e80187fc6706%40%3Cdev.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r58f5b14dc5ae43583db3a7e872419aca97ebe47bcd7f7334f4128016%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r59e0878013d329dcc481eeafebdb0ee445b1e2852d0c4827b1ddaff2%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r5a07f274f355c914054c7357ad6d3456ffaca064f26cd780acb90a9a%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r5a9462096c71593e771602beb0e69357adb5175d9a5c18d5181e0ab4%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r6236ae4adc401e3b2f2575c22865f2f6c6ea9ff1d7b264b40d9602af%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r66e99d973fd79ddbcb3fbdb24f4767fe9b911f5b0abb05d7b6f65801%40%3Ccommits.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r6b83ca85c8f9a6794b1f85bc70d1385ed7bc1ad07750d0977537154a%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r6dfa64ecc3d67c1a71c08bfa04064549179d499f8e20a8285c57bd51%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r6f51a654ac2e67e3d1c65a8957cbbb127c3f15b64b4fcd626df03633%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r70f8bcccd304bd66c1aca657dbfc2bf11f73add9032571b01f1f733d%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r71da5f51ef04cb95abae560425dce9667740cbd567920f516f76efb7%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r73b5a9b677b707bbb7c1469ea746312c47838b312603bada9e382bba%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r761a52f1e214efec286ee80045d0012e955eebaa72395ad62cccbcfc%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r769411eb43dd9ef77665700deb7fc491fc3ceb532914260c90b56f2f%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r77dd041d8025a869156481d2268c67ad17121f64e31f9b4a1a220145%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r7bdc83513c12db1827b79b8d57a7a0975a25d28bc6c5efe590ec1e02%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r7da5ae60d7973e8894cfe92f49ecb5b47417eefab4c77cc87514d3cf%40%3Cdev.felix.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r8045eedd6bb74efcd8e01130796adbab98ee4a0d1273509fb1f2077a%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r819857361f5a156e90d6d06ccf6c41026bc99030d60d0804be3a9957%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r827d17bf6900eddc686f4b6ee16fc5e52ca0070f8df7612222c40ac5%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r874688141495df766e62be095f1dfb0bf4a24ca0340d8e0215c03fab%40%3Cissues.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r87b0c69fef09277333a7e1716926d1f237d462e143a335854ddd922f%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r87d8337300a635d66f0bb838bf635cdfcbba6b92c608a7813adbf4f4%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r8866f0cd2a3b319288b7eea20ac137b9f260c813d10ee2db88b65d32%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r8cacf91ae1b17cc6531d20953c52fa52f6fd3191deb3383446086ab7%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r8dd01541fc49d24ec223365a9974231cbd7378b749247a89b0a52210%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r8fead0144bb84d8714695c43607dca9c5101aa028a431ec695882fe5%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r90b5ac6e2bf190a5297bda58c7ec76d01cd86ff050b2470fcd9f4b35%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r911c1879258ebf98bca172c0673350eb7ea6569ca1735888d4cb7adc%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r916b6542bd5b15a8a7ff8fc14a0e0331e8e3e9d682f22768ae71d775%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r93b240be16e642579ed794325bae31b040e1af896ecc12466642e19d%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r93d5e81e879120d8d87925dbdd4045cb3afa9b066f4370f60b626ce3%40%3Ccommits.druid.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r9b790fe3a93121199f41258474222f15002b2f729495aa7ecbf90718%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r9c010b79140452294292379183e7fe8e3533c5bb4db3f3fb39a6df61%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r9cc76b98f87738791b8ec3736755f92444d3c8cb26bd4e4ffdb5c1cc%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r9cd444f944241dc26d9b8b007fe8971ed7f005b56befef7a4f4fb827%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r9d9b4b93df7f92cdf1147db0fc169be1776c93d1fbc63bc65721fffd%40%3Cdev.knox.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/r9f8c45a2a4540911cd8bd0485f67e8091883c9234d7a3aeb349c46c1%40%3Creviews.iotdb.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/ra1f19625cc67ac1b459c558f2ea5647d71ce51c6fe4f4cb03baec849%40%3Cnotifications.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/ra55e04d5a73afcb8383f4386e2b26832c6e3972e53827021ab885943%40%3Ccommits.shiro.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/ra5b7313d8cc9411db6790adfba33f2cf0665cb77adb7b02043c95867%40%3Cdev.felix.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/raa9c370ab42d737e93bc1795bb6a2187d7c60210cd5e3b3ce8f3c484%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rad255c736fad46135f1339408cb0147d0671e45c376c3be85ceeec1a%40%3Cnotifications.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rae15d73cabef55bad148e4e6449b05da95646a2a8db3fc938e858dff%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/raf9c581b793c30ff8f55f2415c7bd337eb69775aae607bf9ed1b16fb%40%3Cdev.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rafb023a7c61180a1027819678eb2068b0b60cd5c2559cb8490e26c81%40%3Cissues.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rb077d35f2940191daeefca0d6449cddb2e9d06bcf8f5af4da2df3ca2%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rb5f2558ea2ac63633dfb04db1e8a6ea6bb1a2b8614899095e16c6233%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rb69b1d7008a4b3de5ce5867e41a455693907026bc70ead06867aa323%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rb7e159636b26156f6ef2b2a1a79b3ec9a026923b5456713e68f7c18e%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rb81a018f83fe02c95a2138a7bb4f1e1677bd7e1fc1e7024280c2292d%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rb8ad3745cb94c60d44cc369aff436eaf03dbc93112cefc86a2ed53ba%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rb8c007f87dc57731a7b9a3b05364530422535b7e0bc6a0c5b68d4d55%40%3Cdev.felix.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rbc5a622401924fadab61e07393235838918228b3d8a1a6704295b032%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rbc5a8d7a0a13bc8152d427a7e9097cdeb139c6cfe111b2f00f26d16b%40%3Cissues.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rbf99e4495461099cad9aa62e0164f8f25a7f97b791b4ace56e375f8d%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rc1646894341450fdc4f7e96a88f5e2cf18d8004714f98aec6b831b3e%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rc1d9b8e9d17749d4d2b9abaaa72c422d090315bd6bc0ae73a16abc1c%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rc2e24756d28580eeac811c5c6a12012c9f424b6e5bffb89f98ee3d03%40%3Cdev.felix.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rc44d1147f78496ec9932a38b28795ff4fd0c4fa6e3b6f5cc33c14d29%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rc4b972ea10c5a65c6a88a6e233778718ab9af7f484affdd5e5de0cff%40%3Ccommits.felix.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rc77918636d8744d50312e4f67ba2e01f47db3ec5144540df8745cb38%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rc8dd95802be0cca8d7d0929c0c8484ede384ecb966b2a9dc7197b089%40%3Creviews.iotdb.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rc9d2ab8a6c7835182f20b01104798e67c75db655c869733a0713a590%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rccedec4cfd5df6761255b71349e3b7c27ee0745bd33698a71b1775cf%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rcdcf32952397c83a1d617a8c9cd5c15c98b8d0d38a607972956bde7e%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rcdd56ab4255801a0964dcce3285e87f2c6994e6469e189f6836f34e3%40%3Cnotifications.iotdb.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rcfb95a7c69c4b9c082ea1918e812dfc45aa0d1e120fd47f68251a336%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rcff5caebfd535195276aaabc1b631fd55a4ff6b14e2bdfe33f18ff91%40%3Creviews.iotdb.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rd58b60ab2e49ebf21022e59e280feb25899ff785c88f31fe314aa5b9%40%3Ccommits.shiro.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rd7e62e2972a41c2658f41a824b8bdd15644d80fcadc51fe7b7c855de%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rdbf1cd0ab330c032f3a09b453cb6405dccc905ad53765323bddab957%40%3Cissues.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rdddb4b06e86fd58a1beda132f22192af2f9b56aae8849cb3767ccd55%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rde11c433675143d8d27551c3d9e821fe1955f1551a518033d3716553%40%3Cdev.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rde782fd8e133f7e04e50c8aaa4774df524367764eb5b85bf60d96747%40%3Cnotifications.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/re08b03cd1754b32f342664eead415af48092c630c8e3e0deba862a26%40%3Ccommits.shiro.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/re5706141ca397587f7ee0f500a39ccc590a41f802fc125fc135cb92f%40%3Cnotifications.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/ree506849c4f04376793b1a3076bc017da60b8a2ef2702dc214ff826f%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/refbbb0eb65c185d1fa491cee08ac8ed32708ce3b269133a6da264317%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rf00ea6376f3d0e8b8f62cf6d4a4f28b24e27193acd2c851f618aa41e%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rf3bc023a7cc729aeac72f482e2eeeab9008aa6b1dadbeb3f45320cae%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rfd9f102864a039f7fda64a580dfe1a342d65d7b723ca06dc9fbceb31%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rfe5caef1fd6cf4b8ceac1b63c33195f2908517b665c946c020d3fbd6%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rfe6ba83d14545e982400dea89e68b10113cb5202a3dcb558ce64842d%40%3Cissues.zookeeper.apache.org%3E
emo@eclipse.org - https://lists.apache.org/thread.html/rff0ad6a7dac2182421e2db2407e44fbb61a89904adfd91538f21fbf8%40%3Cissues.beam.apache.org%3E
emo@eclipse.org - EXPLOIT,MITIGATION,THIRD_PARTY_ADVISORY
emo@eclipse.org - EXPLOIT,PATCH,VENDOR_ADVISORY
emo@eclipse.org - MAILING_LIST,THIRD_PARTY_ADVISORY
emo@eclipse.org - NOT_APPLICABLE,THIRD_PARTY_ADVISORY
emo@eclipse.org - PATCH,THIRD_PARTY_ADVISORY
emo@eclipse.org - PATCH,THIRD_PARTY_ADVISORY
emo@eclipse.org - PATCH,THIRD_PARTY_ADVISORY
emo@eclipse.org - PATCH,THIRD_PARTY_ADVISORY
emo@eclipse.org - THIRD_PARTY_ADVISORY
emo@eclipse.org - THIRD_PARTY_ADVISORY
Vulnerable Software & Versions: (show all )
CVE-2018-12536 suppress
In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a java.nio.file.InvalidPathException which includes the full path to the base resource directory that the DefaultServlet and/or webapp is using. If this InvalidPathException is then handled by the default Error Handler, the InvalidPathException message is included in the error response, revealing the full server path to the requesting system.
CWE-209 Generation of Error Message Containing Sensitive Information, NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (5.0)
Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N
References:
Vulnerable Software & Versions: (show all )
CVE-2021-28169 suppress
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.
NVD-CWE-Other, CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (5.0)
Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N
References:
Vulnerable Software & Versions: (show all )
CVE-2023-26048 suppress
Jetty is a java based web server and servlet engine. In affected versions servlets with multipart support (e.g. annotated with `@MultipartConfig`) that call `HttpServletRequest.getParameter()` or `HttpServletRequest.getParts()` may cause `OutOfMemoryError` when the client sends a multipart request with a part that has a name but no filename and very large content. This happens even with the default settings of `fileSizeThreshold=0` which should stream the whole part content to disk. An attacker client may send a large multipart request and cause the server to throw `OutOfMemoryError`. However, the server may be able to recover after the `OutOfMemoryError` and continue its service -- although it may take some time. This issue has been patched in versions 9.4.51, 10.0.14, and 11.0.14. Users are advised to upgrade. Users unable to upgrade may set the multipart parameter `maxRequestSize` which must be set to a non-negative value, so the whole multipart content is limited (although still read into memory).
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2023-26049 suppress
Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggle cookies within other cookies, or otherwise perform unintended behavior by tampering with the cookie parsing mechanism. If Jetty sees a cookie VALUE that starts with `"` (double quote), it will continue to read the cookie string until it sees a closing quote -- even if a semicolon is encountered. So, a cookie header such as: `DISPLAY_LANGUAGE="b; JSESSIONID=1337; c=d"` will be parsed as one cookie, with the name DISPLAY_LANGUAGE and a value of b; JSESSIONID=1337; c=d instead of 3 separate cookies. This has security implications because if, say, JSESSIONID is an HttpOnly cookie, and the DISPLAY_LANGUAGE cookie value is rendered on the page, an attacker can smuggle the JSESSIONID cookie into the DISPLAY_LANGUAGE cookie and thereby exfiltrate it. This is significant when an intermediary is enacting some policy based on cookies, so a smuggled cookie can bypass that policy yet still be seen by the Jetty server or its logging system. This issue has been addressed in versions 9.4.51, 10.0.14, 11.0.14, and 12.0.0.beta0 and users are advised to upgrade. There are no known workarounds for this issue.
NVD-CWE-noinfo, CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2023-40167 suppress
Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accepts the `+` character proceeding the content-length value in a HTTP/1 header field. This is more permissive than allowed by the RFC and other servers routinely reject such requests with 400 responses. There is no known exploit scenario, but it is conceivable that request smuggling could result if jetty is used in combination with a server that does not close the connection after sending such a 400 response. Versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1 contain a patch for this issue. There is no workaround as there is no known exploit scenario.
CWE-130 Improper Handling of Length Parameter Inconsistency, NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2024-6763 suppress
Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing.
The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI
differs from the common browsers in how it handles a URI that would be
considered invalid if fully validated against the RRC. Specifically HttpURI
and the browser may differ on the value of the host extracted from an
invalid URI and thus a combination of Jetty and a vulnerable browser may
be vulnerable to a open redirect attack or to a SSRF attack if the URI
is used after passing validation checks.
CWE-1286 Improper Validation of Syntactic Correctness of Input, NVD-CWE-Other
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2021-34428 suppress
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.
CWE-613 Insufficient Session Expiration
CVSSv3:
Base Score: LOW (3.5)
Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:0.9/RC:R/MAV:A
CVSSv2:
Base Score: LOW (3.6)
Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:N
References:
Vulnerable Software & Versions: (show all )
CVE-2023-36479 suppress
Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.
CWE-149 Improper Neutralization of Quoting Syntax, NVD-CWE-Other
CVSSv3:
Base Score: LOW (3.1)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N/E:1.6/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2022-2047 suppress
In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: LOW (2.7)
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N/E:1.2/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (4.0)
Vector: /AV:N/AC:L/Au:S/C:N/I:P/A:N
References:
Vulnerable Software & Versions: (show all )
mortbay-apache-jsp-9.0.111.jar
Description:
A rebundling of Apache Tomcat Jasper to remove the tomcat server dependencies, so that the JSP engine can be used by the Eclipse Jetty project.
License:
http://www.apache.org/licenses/LICENSE-2.0
File Path: /home/runner/.m2/repository/org/mortbay/jasper/mortbay-apache-jsp/9.0.111/mortbay-apache-jsp-9.0.111.jar
MD5: 53d6741c3b444ae10b24f81ca5fc852e
SHA1: 2cf7435e457cc56404832a4b6963312be8a6a53b
SHA256: b81fa4e3646b7c92291b5c962ac3bbbb60a13298a8f4d5d9a6a2bc0a1fcbc5fb
Referenced In Project/Scope: waffle-jetty:provided
mortbay-apache-jsp-9.0.111.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.eclipse.jetty.ee8/jetty-ee8-apache-jsp@12.1.5
Evidence
Type Source Name Value Confidence
Vendor file name mortbay-apache-jsp High
Vendor jar package name apache Highest
Vendor jar package name jasper Highest
Vendor jar package name jsp Highest
Vendor Manifest automatic-module-name org.mortbay.apache.jasper Medium
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-docurl https://eclipse.dev/jetty/ Low
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Vendor Manifest bundle-symbolicname org.mortbay.jasper.mortbay-apache-jsp Medium
Vendor Manifest Implementation-Vendor Eclipse.org - Jetty High
Vendor Manifest url http://www.eclipse.org/jetty Low
Vendor pom artifactid mortbay-apache-jsp Highest
Vendor pom artifactid mortbay-apache-jsp Low
Vendor pom groupid org.mortbay.jasper Highest
Vendor pom name MortBay :: Apache Jasper :: JSP Implementation High
Vendor pom parent-artifactid jasper-jsp Low
Product file name mortbay-apache-jsp High
Product jar package name apache Highest
Product jar package name jasper Highest
Product jar package name jsp Highest
Product jar package name tomcat Highest
Product Manifest automatic-module-name org.mortbay.apache.jasper Medium
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-docurl https://eclipse.dev/jetty/ Low
Product Manifest Bundle-Name Mortbay Jasper Medium
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Product Manifest bundle-symbolicname org.mortbay.jasper.mortbay-apache-jsp Medium
Product Manifest url http://www.eclipse.org/jetty Low
Product pom artifactid mortbay-apache-jsp Highest
Product pom groupid org.mortbay.jasper Highest
Product pom name MortBay :: Apache Jasper :: JSP Implementation High
Product pom parent-artifactid jasper-jsp Medium
Version file version 9.0.111 High
Version Manifest Bundle-Version 9.0.111 High
Version Manifest Implementation-Version 9.0.111 High
Version pom version 9.0.111 Highest
pkg:maven/org.mortbay.jasper/mortbay-apache-jsp@9.0.111
(Confidence :High)
cpe:2.3:a:apache:tomcat:9.0.111:*:*:*:*:*:*:*
(Confidence :Low)
suppress
slf4j-api-2.0.17.jar
Description:
The slf4j API
License:
https://opensource.org/license/mit
File Path: /home/runner/.m2/repository/org/slf4j/slf4j-api/2.0.17/slf4j-api-2.0.17.jar
MD5: b6480d114a23683498ac3f746f959d2f
SHA1: d9e58ac9c7779ba3bf8142aff6c830617a7fe60f
SHA256: 7b751d952061954d5abfed7181c1f645d336091b679891591d63329c622eb832
Referenced In Project/Scope: waffle-jetty:compile
slf4j-api-2.0.17.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name slf4j-api High
Vendor jar package name slf4j Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.slf4j.org Low
Vendor Manifest bundle-symbolicname slf4j.api Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid slf4j-api Highest
Vendor pom artifactid slf4j-api Low
Vendor pom groupid org.slf4j Highest
Vendor pom name SLF4J API Module High
Vendor pom parent-artifactid slf4j-parent Low
Vendor pom url http://www.slf4j.org Highest
Product file name slf4j-api High
Product jar package name slf4j Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.slf4j.org Low
Product Manifest Bundle-Name SLF4J API Module Medium
Product Manifest bundle-symbolicname slf4j.api Medium
Product Manifest Implementation-Title slf4j-api High
Product Manifest multi-release true Low
Product pom artifactid slf4j-api Highest
Product pom groupid org.slf4j Highest
Product pom name SLF4J API Module High
Product pom parent-artifactid slf4j-parent Medium
Product pom url http://www.slf4j.org Medium
Version file version 2.0.17 High
Version Manifest Bundle-Version 2.0.17 High
Version Manifest Implementation-Version 2.0.17 High
Version pom version 2.0.17 Highest
pkg:maven/org.slf4j/slf4j-api@2.0.17
(Confidence :High)
spotbugs-annotations-4.9.8.jar
Description:
Annotations the SpotBugs tool supports
License:
GNU LESSER GENERAL PUBLIC LICENSE, Version 2.1: https://www.gnu.org/licenses/old-licenses/lgpl-2.1.en.html
File Path: /home/runner/.m2/repository/com/github/spotbugs/spotbugs-annotations/4.9.8/spotbugs-annotations-4.9.8.jar
MD5: d4c2e7bd090be697ad409a4e75684a94
SHA1: ca4a2783a6123e67124fd7feb4caccd2e2ac9a73
SHA256: 6f69d6fe9c55a54dcb30e87d8fa2d5f52246af50d7a3445246d9539ef221be1c
Referenced In Project/Scope: waffle-jetty:provided
spotbugs-annotations-4.9.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-jetty@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name spotbugs-annotations High
Vendor Manifest automatic-module-name com.github.spotbugs.annotations Medium
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Vendor Manifest bundle-symbolicname spotbugs-annotations Medium
Vendor pom artifactid spotbugs-annotations Highest
Vendor pom artifactid spotbugs-annotations Low
Vendor pom developer email andreas.sewe@codetrails.com Low
Vendor pom developer email dbrosius@mebigfatguy.com Low
Vendor pom developer email loskutov@gmx.de Low
Vendor pom developer email skypencil@gmail.com Low
Vendor pom developer id henrik242 Medium
Vendor pom developer id iloveeclipse Medium
Vendor pom developer id jsotuyod Medium
Vendor pom developer id KengoTODA Medium
Vendor pom developer id mebigfatguy Medium
Vendor pom developer id sewe Medium
Vendor pom developer id ThrawnCA Medium
Vendor pom developer name Andreas Sewe Medium
Vendor pom developer name Andrey Loskutov Medium
Vendor pom developer name Dave Brosius Medium
Vendor pom developer name Juan Martín Sotuyo Dodero Medium
Vendor pom developer name Kengo TODA Medium
Vendor pom groupid com.github.spotbugs Highest
Vendor pom name SpotBugs Annotations High
Vendor pom url https://spotbugs.github.io/ Highest
Product file name spotbugs-annotations High
Product Manifest automatic-module-name com.github.spotbugs.annotations Medium
Product Manifest Bundle-Name spotbugs-annotations Medium
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Product Manifest bundle-symbolicname spotbugs-annotations Medium
Product pom artifactid spotbugs-annotations Highest
Product pom developer email andreas.sewe@codetrails.com Low
Product pom developer email dbrosius@mebigfatguy.com Low
Product pom developer email loskutov@gmx.de Low
Product pom developer email skypencil@gmail.com Low
Product pom developer id henrik242 Low
Product pom developer id iloveeclipse Low
Product pom developer id jsotuyod Low
Product pom developer id KengoTODA Low
Product pom developer id mebigfatguy Low
Product pom developer id sewe Low
Product pom developer id ThrawnCA Low
Product pom developer name Andreas Sewe Low
Product pom developer name Andrey Loskutov Low
Product pom developer name Dave Brosius Low
Product pom developer name Juan Martín Sotuyo Dodero Low
Product pom developer name Kengo TODA Low
Product pom groupid com.github.spotbugs Highest
Product pom name SpotBugs Annotations High
Product pom url https://spotbugs.github.io/ Medium
Version file version 4.9.8 High
Version Manifest Bundle-Version 4.9.8 High
Version pom version 4.9.8 Highest
pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8
(Confidence :High)